Authorization Bypass in Create WordPress Plugin
CVE-2026-16992

Currently unrated

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
9 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-16992?

The Create WordPress plugin versions prior to 2.5.4 contain a significant vulnerability where an authorization check is not enforced on certain REST API routes. This oversight allows attackers to access unpublished content without authentication, potentially leading to unauthorized exposure of sensitive information. Furthermore, this flaw enables attackers to publish the content they access, worsening the situation by making it publicly available without the consent of the author. It is crucial for operators using this plugin to update to the latest version to mitigate the risk of such unauthorized access.

Affected Version(s)

Create 0 < 2.5.4

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pedro Pinho
WPScan
.