PatchSiren cyber security CVE debrief
CVE-2026-65490 John-Michael L'Allier CVE debrief
A vulnerability in the Create mediavine-create plugin allows retrieval of embedded sensitive data. This issue affects Create from n/a through 2.6.0. The vulnerability can lead to exposure of sensitive information, which could be accessed by unauthorized parties. Defenders should assess the potential impact and prioritize remediation efforts accordingly. The Create mediavine-create plugin versions up to 2.6.0 are affected, and defenders should verify potential exposure and assess the impact on systems using the affected plugin versions.
- Vendor
- John-Michael L'Allier
- Product
- Create
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-23
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-07-23
- Advisory updated
- 2026-09-18
Who should care
Defenders of systems using Create mediavine-create plugin versions up to 2.6.0 should assess exposure and prioritize remediation. This includes operators, administrators, and security teams responsible for maintaining the affected systems. They should verify potential exposure, assess the impact on systems using the affected plugin versions, and prioritize remediation efforts accordingly. The vulnerability's impact
Why it matters
Defenders should assess exposure and prioritize remediation of Create mediavine-create plugin versions up to 2.6.0 due to sensitive data exposure vulnerability.
- Verify potential exposure of sensitive data
- Assess impact on systems using affected plugin versions
- Prioritize remediation of vulnerable systems
Technical summary
The Create mediavine-create plugin is vulnerable to sensitive data exposure, affecting versions from n/a through 2.6.0. This vulnerability allows unauthorized access to sensitive information, which could lead to security breaches. The technical details of the vulnerability are based on the available information from the CVE record and NVD entry. Defenders should assess the technical impact and prioritize remediation efforts to prevent potential security breaches.
Defensive priority
Assess exposure, prioritize remediation
Recommended defensive actions
- Assess exposure of Create mediavine-create plugin versions up to 2.6.0
- Prioritize remediation of affected systems
- Verify vendor remediation status
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. The details are based on the available data from these sources, and further verification is recommended to confirm the extent of the vulnerability. The evidence is limited to publicly available information, and defenders should be cautious when assessing the vulnerability. Additional verification tasks are necessary to confirm the vulnerability's impact and to identify potential mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-65490 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-65490
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-65490 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-65490
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.