What is CVE-2026-24552?
CVE-2026-24552 is a SQL injection vulnerability in the 'Create by Mediavine' plugin versions 2.5.3 and below that can be exploited by users with the 'Contributor' role. This could allow unauthorized access to the database. Users should update the plugin to the latest version immediately.
Azərbaycanca: CVE-2026-24552, 'Create by Mediavine' plaginin 2.5.3 və daha əvvəlki versiyalarında 'Contributor' roluna malik istifadəçilər tərəfindən SQL injection hücumuna imkan verən zəiflikdir. Bu zəiflikdən istifadə edərək hücumçu verilənlər bazasına icazəsiz giriş əldə edə bilər. Plagindən istifadə edən istifadəçilər dərhal ən son versiyaya yeniləmə etməlidirlər.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the 'Create by Mediavine' plugin are affected by the CVE-2026-24552 SQL injection vulnerability?
The vulnerability affects plugin versions 2.5.3 and below.
What user role level is required to exploit the CVE-2026-24552 vulnerability?
An attacker needs to have the 'Contributor' role to carry out this SQL injection attack.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.