AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18786

HIGH · CVSS 8.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The CheckView WordPress plugin prior to version 2.3.2 is vulnerable due to improper handling of REST API authentication, allowing unauthenticated attackers to bypass nonce checks. This flaw enables attackers to execute any REST action available to an administrator, including creating new admin accounts, by tricking an administrator into clicking a malicious link. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-18786
Severity
HIGH
CVSS
8.8
EPSS
0.29%
WordPress

Original NVD Description

The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose URI merely contains a CheckView WordPress plugin before 2.3.2-specific string, making it possible for unauthenticated attackers to bypass the REST nonce check and perform any REST action available to a logged-in administrator, such as creating a new administrator account, via a crafted link an administrator is tricked into opening.