What is CVE-2026-16992?
This vulnerability exists in the Create WordPress plugin before version 2.5.4 due to a missing authorization check on a REST API route, which also publishes content as a side effect. It allows unauthenticated attackers to read unpublished content and make it publicly accessible. Updating to the latest plugin version is recommended.
Azərbaycanca: Bu boşluq Create WordPress plaginində (2.5.4-dən əvvəlki versiyalar) REST API marşrutunda authorization yoxlamasının olmaması səbəbindən baş verir. Nəticədə, autentifikasiya olunmamış hücumçular dərc olunmamış məzmunu oxuya və əlavə olaraq həmin məzmunu ictimaiyyətə açıq hala gətirə bilərlər. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
In which plugin was CVE-2026-16992 discovered and what causes it?
CVE-2026-16992 was discovered in the Create WordPress plugin before version 2.5.4. The vulnerability is caused by a missing authorization check on a REST API route.
What can unauthenticated attackers do by exploiting CVE-2026-16992?
By exploiting CVE-2026-16992, unauthenticated attackers can read unpublished content and make it publicly accessible.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.