---
id: CVE-2026-18037
title: >-
  The Create WordPress plugin before 2.5.4 does not perform an authorization
  check before rendering content over one of its public REST API routes, and
  that route additionally publishes the requested content as a side effect,
  allowing unau…
summary: >-
  The Create WordPress plugin before 2.5.4 does not perform an authorization
  check before rendering content over one of its public REST API routes, and
  that route additionally publishes the requested content as a side effect,
  allowing unau…
severity: none
published: '2026-08-09'
updated: '2026-08-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18037'
references:
  - url: 'https://wpscan.com/vulnerability/cd61ce2a-94ce-4ce3-a592-b7329f118f94/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00275
epssPercentile: 0.17671
ingestedAt: '2026-08-09T15:33:38.262Z'
---

## Overview

The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
