CVE-2026-13200 Overview
The Create by Mediavine plugin for WordPress contains a SQL Injection vulnerability in the order parameter of its advanced-filter query branch. The flaw affects all versions up to and including 2.5.3. Insufficient escaping of user-supplied input and a lack of prepared statements allow authenticated users with author-level access or higher to append arbitrary SQL to existing queries. Successful exploitation lets attackers extract sensitive information from the WordPress database, including user credentials and session data. The vulnerability is tracked under CWE-89 — Improper Neutralization of Special Elements used in an SQL Command.
Critical Impact
Authenticated attackers with author privileges can exfiltrate arbitrary data from the WordPress database via crafted order parameter payloads.
Affected Products
- Create by Mediavine WordPress plugin — all versions through 2.5.3
- WordPress sites where the plugin is installed and active
- Sites permitting author-level or higher user registration
Discovery Timeline
- 2026-09-19 - CVE-2026-13200 published to NVD
- 2026-09-21 - Last updated in NVD database
Technical Details for CVE-2026-13200
Vulnerability Analysis
The vulnerability exists in the Creations API of the Create plugin, specifically in the advanced-filter SQL branch of class-creations-api.php. When the plugin builds the SQL query for filtered creations, the order parameter is concatenated into the query string without proper escaping or use of $wpdb->prepare(). This lets an attacker append additional SQL statements to the executing query.
The vulnerable branch is only reached when the request includes one of the following parameters: linked_posts, created_after, created_before, missing_fields, post_id, a comma-separated type value, or exclude_type. Attackers must satisfy this precondition to trigger the injection path.
Exploitation requires authenticated access at the author role or above, which limits the vulnerability's reach on hardened sites. However, WordPress deployments that allow open contributor or author registration remain exposed to credential and data theft.
Root Cause
The root cause is a failure to parameterize the order clause in the query built at class-creations-api.php line 329 and line 334, combined with an unsafe passthrough in the database interface at class-mv-dbi.php line 1022. The plugin trusts client-supplied ordering directives and inserts them directly into the SQL string.
Attack Vector
An authenticated attacker sends a crafted HTTP request to the plugin's Creations API endpoint. The request includes one of the qualifying filter parameters (for example, post_id) and a malicious order value containing SQL syntax such as a UNION SELECT fragment. The database engine executes the injected clause and returns results to the response, enabling data extraction from tables including wp_users and wp_usermeta.
Refer to the Wordfence Vulnerability Report and the WordPress Changeset Review for the code-level fix details.
Detection Methods for CVE-2026-13200
Indicators of Compromise
- HTTP requests to the Create plugin's REST endpoints containing SQL keywords such as UNION, SELECT, SLEEP, or INFORMATION_SCHEMA in the order query parameter.
- Requests combining the order parameter with linked_posts, created_after, created_before, missing_fields, post_id, type, or exclude_type from author-level accounts.
- Unexpected outbound data volumes or slow response times on Creations API endpoints, suggesting time-based or UNION-based extraction.
Detection Strategies
- Inspect web server and WordPress access logs for anomalous order parameter values containing quoting characters, comments (--, #), or SQL operators.
- Enable WordPress query logging or database audit logging to identify malformed or non-standard ORDER BY clauses hitting the wp_mv_create tables.
- Deploy web application firewall rules that flag SQL metacharacters in requests targeting /wp-json/mv-create/ routes.
Monitoring Recommendations
- Alert on repeated 4xx or 5xx responses from Create plugin endpoints following requests from newly registered author accounts.
- Correlate author role assignments with subsequent API activity to identify account misuse.
- Monitor database query duration percentiles for anomalies indicating time-based blind SQL injection attempts.
How to Mitigate CVE-2026-13200
Immediate Actions Required
- Update the Create by Mediavine plugin to a version later than 2.5.3 as soon as a patched release is available from the vendor.
- Audit WordPress user accounts and revoke unnecessary author-level and higher privileges.
- Disable open user registration or restrict new account roles to subscriber until patching is complete.
Patch Information
A fix was committed in the plugin repository as tracked by WordPress Changeset 3627606. Administrators should upgrade to the first released version incorporating this changeset. Consult the Wordfence Vulnerability Report for the current fixed version.
Workarounds
- Deactivate the Create by Mediavine plugin until the patched version is deployed if immediate updating is not feasible.
- Deploy a web application firewall rule that blocks requests to Create plugin endpoints containing SQL metacharacters in the order parameter.
- Restrict access to /wp-json/mv-create/ endpoints by IP allowlist or authentication proxy where the plugin is only used administratively.
# Example WAF rule concept (ModSecurity syntax)
SecRule REQUEST_URI "@contains /wp-json/mv-create/" \
"chain,phase:2,deny,status:403,id:1026013200,\
msg:'CVE-2026-13200 SQLi attempt in order parameter'"
SecRule ARGS:order "@rx (?i)(union|select|sleep|information_schema|--|#)" \
"t:none,t:urlDecode"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
