Executive brief
The Create by Mediavine plugin for WordPress, which is used by content creators to build recipes and lists, contains a security flaw that exposes sensitive information. An unauthorized person can access data that should be private, potentially revealing system details or configuration information. This could be used by an attacker to plan further, more damaging attacks against the website.
Technical details
A sensitive data exposure vulnerability (CWE-497) exists in the Create by Mediavine plugin for WordPress through version 2.5.3. The flaw allows an unauthenticated remote attacker to access sensitive system or configuration information that is normally restricted. The vulnerability stems from improper control of information exposure within the plugin's environment. An attacker can exploit this over the network without any user interaction or prior authentication. As of the advisory date, no official patch has been confirmed, and users are advised to monitor for updates from the developer.
Affected products
- Mediavine (mischiefmarmot) Create by Mediavine <= 2.5.3
Timeline
- 2026-02-09: other: Reported by Que Thanh Tuan
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: disclosed: NVD publication date