Junglewise Threat Intelligence

CVE-2026-24552: Mediavine Create SQL injection in WordPress plugin

CVE-2026-24552 · Severity: high · CVSS 8.5 · Published 2026-07-23

Technologies: Mediavine Create. Vendors: Mediavine.

Executive brief

Create by Mediavine is a WordPress plugin used by content creators to build and display recipe cards, craft instructions, and lists. A security flaw allows users with 'Contributor' level access to perform unauthorized database queries. This could lead to the exposure of sensitive site information or disruption of website operations.

Technical details

The Create by Mediavine plugin for WordPress (versions <= 2.5.3) contains a SQL injection vulnerability due to improper neutralization of special elements used in an SQL command (CWE-89). The vulnerability requires 'Contributor' level authentication (PR:L) and can be exploited over the network without user interaction. An attacker with these privileges can execute arbitrary SQL queries against the WordPress database, potentially leading to sensitive data exfiltration or limited service disruption. As of the advisory date, no official patch has been released.

Affected products

  • Mediavine Create by Mediavine <= 2.5.3

Timeline

  • 2025-12-24: other: Vulnerability reported by researcher Nabil Irawan
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: CVE published to NVD dataset

References

Related threats