A vulnerability identified as problematic has been detected in Create Plugin up to 2.5.3 on WordPress. Impacted is an unknown function of the component REST API. Performing a manipulation results in missing authorization.

This vulnerability is cataloged as CVE-2026-18037. It is possible to initiate the attack remotely. There is no exploit available.

You should upgrade the affected component.