CVE-2026-13191 | mischiefmarmot Create Plugin up to 2.5.3 on WordPress REST Endpoint order_by sql injection
A vulnerability, which was classified as critical, was found in mischiefmarmot Create Plugin up to 2.5.3 on WordPress. This impacts an unknown function of the component REST Endpoint. Executing a manipulation of the argument order_by can lead to sql injection.
This vulnerability appears as CVE-2026-13191. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More