Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in John-Michael L'Allier Create mediavine-create allows Retrieve Embedded Sensitive Data.This issue affects Create: from n/a through 2.6.0.
Published: 2026-07-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Upgrade
AI Analysis

Impact

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in the WordPress Create by Mediavine plugin, developed by John‑Michael L'Allier, allows an attacker to retrieve embedded sensitive data. The issue affects plugin versions from n/a through 2.6.0. Because the plugin fails to enforce proper access controls, any site visitor can read data intended to be confidential, possibly exposing user details, configuration settings, or other private information.

Affected Systems

WordPress sites that host the Create by Mediavine plugin from John‑Michael L'Allier. Specifically any site running plugin version 2.6.0 or earlier is affected, while sites updated to newer releases are presumed safe.

Risk and Exploitability

The vulnerability scores a CVSS of 5.3, indicating moderate severity, and the EPSS score is below 1%, suggesting a low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that the attack vector is remote and requires only access to the website’s URL space, with no authentication needed to trigger the exposure.

Generated by OpenCVE AI on September 21, 2026 at 07:22 UTC.

Remediation

Vendor Solution

Update the WordPress Create plugin to the latest available version (at least 2.6.1).


OpenCVE Recommended Actions

  • Apply the official patch by upgrading the Create by Mediavine plugin to the latest release after 2.6.0
  • If an upgrade is not feasible, deactivate or uninstall the plugin to eliminate the vulnerable code
  • Conduct a review to detect and remove any sensitive data that may have been exposed while the vulnerable plugin was active

Generated by OpenCVE AI on September 21, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions. Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in John-Michael L'Allier Create mediavine-create allows Retrieve Embedded Sensitive Data.This issue affects Create: from n/a through 2.6.0.
Title WordPress Create by Mediavine plugin <= 2.5.3 - Sensitive Data Exposure vulnerability WordPress Create by Mediavine plugin <= 2.6.0 - Sensitive Data Exposure vulnerability

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Mischiefmarmot
Mischiefmarmot create By Mediavine
Wordpress
Wordpress wordpress
Vendors & Products Mischiefmarmot
Mischiefmarmot create By Mediavine
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.
Title WordPress Create by Mediavine plugin <= 2.5.3 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Mischiefmarmot Create By Mediavine
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-18T16:15:24.802Z

Reserved: 2026-07-22T08:53:35.327Z

Link: CVE-2026-65490

cve-icon Vulnrichment

Updated: 2026-07-23T14:37:40.396Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:42.187

Modified: 2026-09-18T17:16:59.767

Link: CVE-2026-65490

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T07:30:08Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere