Critical Authorization Bypass Vulnerability (CVE-2026-18037) Discovered in Create WordPress Plugin
A critical authorization bypass vulnerability (CVE-2026-18037) has been identified in the Create WordPress plugin versions prior to 2.5.4. This flaw allows unauthenticated attackers to read unpublished content and make it publicly available by exploiting a public REST API route that lacks proper authorization checks.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai