Description
The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable advanced-filter SQL branch is only entered when at least one of the following parameters is present in the request: linked_posts, created_after, created_before, missing_fields, post_id, a comma-separated type value, or exclude_type.
Published: 2026-09-19
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authenticated SQL Injection
Action: Patch
AI Analysis

Impact

The Create plugin for WordPress permits authenticated users with author or higher privileges to inject arbitrary SQL code through the "order" parameter. Insufficient escaping and no parameterization allow malicious queries to be appended to existing statements, enabling the extraction of sensitive database contents. This flaw is a classic SQL injection vulnerability classified as CWE-89, exposing confidentiality risks to the site’s data layer.

Affected Systems

All installations of the mischiefmarmot Create plugin version 2.5.3 or earlier are affected. Users deploying these plugin releases on any WordPress site should evaluate whether the plugin is required or can be upgraded to the latest available version, which removes the insecure 'order' handling code.

Risk and Exploitability

The CVSS base score is 6.5, indicating a moderate severity. EPSS indicates a very low probability of exploitation, and the vulnerability is not included in the CISA KEV catalog. Successful exploitation requires valid author‑level credentials and relies on the plugin’s internal API endpoints. Consequently, the attack surface is limited to authenticated users, but the confidentiality impact can be significant due to the ability to read arbitrary data from the database.

Generated by OpenCVE AI on September 19, 2026 at 23:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Create plugin to a version newer than 2.5.3, ensuring the 'order' parameter sanitization is applied.
  • Limit author‑level accounts to only necessary roles and consider disabling the plugin for users who do not require its functionality.
  • Apply a web application firewall or configure input validation rules to reject suspicious characters in the 'order' parameter as an interim mitigation.

Generated by OpenCVE AI on September 19, 2026 at 23:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Mischiefmarmot
Mischiefmarmot create
Wordpress
Wordpress wordpress
Vendors & Products Mischiefmarmot
Mischiefmarmot create
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable advanced-filter SQL branch is only entered when at least one of the following parameters is present in the request: linked_posts, created_after, created_before, missing_fields, post_id, a comma-separated type value, or exclude_type.
Title Create <= 2.5.3 - Authenticated (Author+) SQL Injection via 'order' Parameter
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Mischiefmarmot Create
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:22.473Z

Reserved: 2026-06-24T13:56:57.028Z

Link: CVE-2026-13200

cve-icon Vulnrichment

Updated: 2026-09-19T13:52:07.207Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T08:16:52.200

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-13200

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:03:25Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')