AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16992

MEDIUM · CVSS 6.5 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-09 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Create WordPress plugin prior to version 2.5.4 lacks proper authorization checks on its REST API routes, enabling unauthenticated attackers to access and publish unpublished content. This vulnerability poses a significant risk to site confidentiality and content integrity. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-16992
Severity
MEDIUM
CVSS
6.5
EPSS
0.16%
WordPress

Original NVD Description

The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.