---
id: CVE-2026-16992
title: >-
  The Create WordPress plugin before 2.5.4 does not perform an authorization
  check before returning content over one of its REST API routes, and that route
  additionally publishes the requested content as a side effect, allowing
  unauthentic…
summary: >-
  The Create WordPress plugin before 2.5.4 does not perform an authorization
  check before returning content over one of its REST API routes, and that route
  additionally publishes the requested content as a side effect, allowing
  unauthentic…
severity: none
published: '2026-08-09'
updated: '2026-08-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16992'
references:
  - url: 'https://wpscan.com/vulnerability/d85653f7-8556-4bac-8860-fbacc63ba5df/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00164
epssPercentile: 0.06087
ingestedAt: '2026-08-09T15:33:38.075Z'
---

## Overview

The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
