← WordPress Vulnerabilities
WordPress security by component

CheckView

CheckView is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 10, 2026; the highest published CVSS base score is 8.8.

Plugin slug: checkview

CVE-2026-18786: CheckView authentication filter permits administrator REST actions

CheckView before 2.3.2 applies its REST authentication filter beyond its own routes and discards the authentication error for any request whose URI contains a CheckView-specific string. An unauthenticated attacker can use a crafted link to bypass the REST nonce check in an Administrator's browser and invoke REST actions available to that Administrator, including creation of a new administrator account. The CNA does not disclose the URI string, authentication-filter function, crafted-link format, or exact account-creation route.

PublishedAug 10, 2026
Known safe version2.3.2
Published vulnerabilities for checkview
Safe version
Aug 10, 2026 CVE-2026-18786
CheckView authentication filter permits administrator REST actions
CheckView before 2.3.2 applies its REST authentication filter beyond its own routes and discards the authentication error for any request whose URI contains a CheckView-specific string. An unauthenticated attacker can use a crafted link to bypass the REST nonce check in an Administrator's browser and invoke REST actions available to that Administrator, including creation of a new administrator account. The CNA does not disclose the URI string, authentication-filter function, crafted-link format, or exact account-creation route.
2.3.2
CVE8.8
NVDPending
Jun 25, 2026 CVE-2026-54844
CheckView Automated Testing: Broken access control
CheckView Automated Testing is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 2.1.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
2.2.0
CVE7.5
NVDPending