What is CVE-2026-18037?
This vulnerability exists in the "Create" WordPress plugin before version 2.5.4, allowing unauthenticated attackers to read unpublished content via a public REST API route that lacks an authorization check. It is recommended to update the plugin to at least version 2.5.4 to mitigate the issue.
Azərbaycanca: Bu zəiflik "Create" WordPress plaginin 2.5.4-dən əvvəlki versiyalarında aşkarlanıb və autentifikasiya olunmamış istifadəçilərə REST API vasitəsilə dərc olunmamış məzmunu oxumağa imkan verir. Problemin həlli üçün plagini ən azı 2.5.4 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What does the CVE-2026-18037 vulnerability in the "Create" WordPress plugin allow?
This vulnerability allows unauthenticated attackers to read unpublished content via a public REST API route that lacks an authorization check.
How to mitigate the CVE-2026-18037 vulnerability?
It is recommended to update the "Create" plugin to at least version 2.5.4 to mitigate the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.