Critical Authorization Bypass Vulnerability (CVE-2026-18037) Discovered in Create WordPress Plugin

A critical authorization bypass vulnerability (CVE-2026-18037) has been identified in the Create WordPress plugin versions prior to 2.5.4. This flaw allows unauthenticated attackers to read unpublished content and make it publicly available by exploiting a public REST API route that lacks proper authorization checks.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai