High severity8.8NVD Advisory· Published Aug 10, 2026· Updated Aug 26, 2026
CVE-2026-18786
CVE-2026-18786
Description
The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose URI merely contains a CheckView WordPress plugin before 2.3.2-specific string, making it possible for unauthenticated attackers to bypass the REST nonce check and perform any REST action available to a logged-in administrator, such as creating a new administrator account, via a crafted link an administrator is tricked into opening.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
1- WordPress Plugins: 25 Vulnerabilities Disclosed in Single-Day Batch, Affecting Multiple Core FunctionsVypr Intelligence · Aug 10, 2026