CVE-2026-24552

WordPress Create by Mediavine plugin <= 2.5.3 - SQL Injection vulnerability

Contributor SQL Injection in Create by Mediavine <= 2.5.3 versions.


We have discovered 639 live websites that are affected by CVE-2026-24552.

Run a Free Instant Scan




Affected Software

Product  Mediavine Create
Category Wordpress Plugins
Vulnerable Domains639 live websites (100% of Mediavine Create install base)
Vulnerable Versions
  • from 0 through 2.5.3
Vulnerable Versions Count39 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Jul 23, 2026
  • Updated - Jul 23, 2026

Credits

  • Nabil Irawan | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-24552
United States556 websites



GB25 websites
France22 websites
Canada10 websites
Bulgaria3 websites
Singapore3 websites
Australia2 websites
Cyprus2 websites
Germany2 websites

Website Distribution by TLD

Number of websites using CVE-2026-24552
.com601 websites
.net14 websites
.ca6 websites
.co4 websites
.org4 websites
.co.uk2 websites
.com.au2 websites
.nl2 websites
.de1 websites
.info1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-24552

Top websites that are affected by CVE-2026-24552. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.net United States***,***
************.com United States***,***
*******************.com United States***,***
****************.com United States***,***
***************.com United States***,***
*****************.com United States***,***
****************.com United States***,***
*****************************.com United States***,***
*************.com GB***,***
****************.com France***,***
See full domain list

FAQ

CVE-2026-24552 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Mediavine Create
A total of 639 websites have been identified as vulnerable to CVE-2026-24552, based on global website indexing conducted by WebTechSurvey.
The Mediavine Create is affected by the CVE-2026-24552 vulnerability.
Mediavine Create versions up to and including 2.5.3 are vulnerable to CVE-2026-24552.