VYPR

Create

by WordPress

CVEs (5)

  • CVE-2026-13191MedSep 19, 2026
    risk 0.42cvss 6.5epss 0.00

    The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…

  • CVE-2026-18037MedAug 9, 2026
    risk 0.42cvss 6.5epss 0.00

    The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished…

  • CVE-2026-16992MedAug 9, 2026
    risk 0.42cvss 6.5epss 0.00

    The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content…

  • CVE-2024-5601MedJun 27, 2024
    risk 0.35cvss 6.4epss 0.00

    The Create by Mediavine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Schema Meta shortcode in all versions up to, and including, 1.9.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

  • CVE-2024-47356MedOct 6, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchthemes Create create allows Stored XSS.This issue affects Create: from n/a through <= 2.9.1.