CVE-2026-13191 Overview
CVE-2026-13191 is a SQL Injection vulnerability in the Mediavine Create plugin for WordPress affecting all versions up to and including 2.5.3. The flaw resides in the handling of the order_by parameter, which is passed into database queries without sufficient escaping or preparation. Authenticated users with Author-level access or higher can append arbitrary SQL to existing queries and extract sensitive data from the WordPress database. The vulnerability is reachable through a REST endpoint whose permission callback defaults to the publish_posts capability, lowering the barrier to exploitation on multi-author sites.
Critical Impact
Authenticated attackers with Author-level access can exfiltrate arbitrary database contents, including user credentials and session tokens, through a REST API endpoint exposed by the plugin.
Affected Products
- Mediavine Create plugin for WordPress, versions up to and including 2.5.3
- WordPress sites exposing the plugin's REST endpoints to Author-level users
- Any site relying on the default publish_posts permission callback for plugin routes
Discovery Timeline
- 2026-09-19 - CVE-2026-13191 published to the National Vulnerability Database (NVD)
- 2026-09-21 - Last updated in NVD database
Technical Details for CVE-2026-13191
Vulnerability Analysis
The vulnerability is a generic SQL Injection ([CWE-89]) in the Mediavine Create plugin. The order_by parameter accepted by the plugin's REST API is concatenated into a SQL query without proper preparation using $wpdb->prepare() or an equivalent parameterization mechanism. Because the plugin also does not enforce a strict allowlist for orderable columns, attackers can inject SQL fragments such as UNION SELECT clauses to read data from any table the WordPress database user can access.
Exploitation requires an authenticated account holding the publish_posts capability, which corresponds to the standard WordPress Author role. On sites that allow guest posting, contributor promotion, or self-registration into elevated roles, this precondition is trivial to meet. Successful exploitation compromises confidentiality of stored data, including wp_users password hashes, session tokens in wp_usermeta, and any additional secrets other plugins persist to the database.
Root Cause
The root cause is insufficient sanitization of user-supplied input combined with the absence of prepared statements around the order_by clause in the plugin's database interface layer. The REST endpoint permission callback grants access based on the low-privilege publish_posts capability, which does not align with the sensitivity of the underlying query.
Attack Vector
An authenticated attacker sends a crafted HTTP request to the vulnerable REST endpoint exposed by the plugin. The order_by parameter carries the injected SQL payload, which the plugin appends to a query executed against the WordPress database. Responses returned by the endpoint reveal data extracted via the injected clauses. No user interaction is required beyond initial authentication.
Code-level references for the vulnerable paths are available in the WordPress API Services Code, the WordPress DBI Class Code, and the WordPress Products Class Code. No public exploit code is currently available.
Detection Methods for CVE-2026-13191
Indicators of Compromise
- REST API requests to Mediavine Create plugin routes containing SQL keywords such as UNION, SELECT, SLEEP(, or INFORMATION_SCHEMA in the order_by parameter.
- Unexpected 500-series responses or unusually large response bodies from plugin endpoints handling order_by.
- Author-level accounts issuing repeated requests to plugin REST routes outside normal content-authoring workflows.
Detection Strategies
- Inspect web server and WordPress request logs for order_by values that contain characters outside a strict alphanumeric column allowlist.
- Enable WordPress database query logging in staging environments and alert on queries containing concatenated ORDER BY clauses derived from REST input.
- Correlate authentication events for Author-level users with subsequent REST calls to /wp-json/mv-create/ routes to identify anomalous access patterns.
Monitoring Recommendations
- Deploy a Web Application Firewall (WAF) rule set that flags SQL metacharacters in the order_by parameter on plugin REST endpoints.
- Monitor for privilege changes that grant publish_posts to previously untrusted accounts.
- Track outbound traffic from the WordPress host for large data transfers that may indicate database exfiltration.
How to Mitigate CVE-2026-13191
Immediate Actions Required
- Update the Mediavine Create plugin to a version later than 2.5.3 as soon as a fixed release is available from the vendor.
- Audit all WordPress user accounts and remove or downgrade unnecessary Author-level and higher privileges.
- Rotate WordPress user passwords, secret keys in wp-config.php, and any API tokens stored in the database if compromise is suspected.
Patch Information
Review the vendor's remediation in the WordPress Code Changeset and the Wordfence Vulnerability Report for the authoritative fix and version guidance. Apply the update across all WordPress environments including staging and disaster-recovery sites.
Workarounds
- Restrict access to the plugin's REST endpoints at the WAF or reverse-proxy layer until the patch is applied.
- Temporarily disable the Mediavine Create plugin on sites where Author-level accounts are not fully trusted.
- Enforce a stricter permission callback that requires the edit_others_posts or manage_options capability for the affected routes via a custom mu-plugin.
# Example: disable the plugin from the command line using WP-CLI
wp plugin deactivate mediavine-create
wp plugin update mediavine-create
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
