SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-24552

HIGH · CVSS 8.5 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The vulnerability exists in the Create by Mediavine plugin versions 2.5.3 and earlier, allowing for SQL injection attacks that could enable unauthorized access to sensitive data or manipulation of the database. Organizations using this plugin should prioritize patching or upgrading to mitigate the risk of exploitation, as the high severity rating indicates a significant potential impact on data integrity and confidentiality.

CVE
CVE-2026-24552
Severity
HIGH
CVSS
8.5
EPSS
0.21%

Original NVD Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'Allier Create allows Blind SQL Injection. This issue affects Create: from n/a through 2.5.3.