Impact
The Create plugin for WordPress permits authenticated users with author or higher privileges to inject arbitrary SQL code through the "order" parameter. Insufficient escaping and no parameterization allow malicious queries to be appended to existing statements, enabling the extraction of sensitive database contents. This flaw is a classic SQL injection vulnerability classified as CWE-89, exposing confidentiality risks to the site’s data layer.
Affected Systems
All installations of the mischiefmarmot Create plugin version 2.5.3 or earlier are affected. Users deploying these plugin releases on any WordPress site should evaluate whether the plugin is required or can be upgraded to the latest available version, which removes the insecure 'order' handling code.
Risk and Exploitability
The CVSS base score is 6.5, indicating a moderate severity. EPSS indicates a very low probability of exploitation, and the vulnerability is not included in the CISA KEV catalog. Successful exploitation requires valid author‑level credentials and relies on the plugin’s internal API endpoints. Consequently, the attack surface is limited to authenticated users, but the confidentiality impact can be significant due to the ability to read arbitrary data from the database.
OpenCVE Enrichment