WordPress security by component
CheckView
Plugin description
CheckView is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 10, 2026; the highest published CVSS base score is 8.8.
Plugin slug:
checkviewLatest vulnerability
CVE-2026-18786: CheckView authentication filter permits administrator REST actions
CheckView before 2.3.2 applies its REST authentication filter beyond its own routes and discards the authentication error for any request whose URI contains a CheckView-specific string. An unauthenticated attacker can use a crafted link to bypass the REST nonce check in an Administrator's browser and invoke REST actions available to that Administrator, including creation of a new administrator account. The CNA does not disclose the URI string, authentication-filter function, crafted-link format, or exact account-creation route.
| Safe version |
|
||
|---|---|---|---|
| Aug 10, 2026 |
CVE-2026-18786
CheckView authentication filter permits administrator REST actions
CheckView before 2.3.2 applies its REST authentication filter beyond its own routes and discards the authentication error for any request whose URI contains a CheckView-specific string. An unauthenticated attacker can use a crafted link to bypass the REST nonce check in an Administrator's browser and invoke REST actions available to that Administrator, including creation of a new administrator account. The CNA does not disclose the URI string, authentication-filter function, crafted-link format, or exact account-creation route.
|
2.3.2 |
CVE8.8
NVDPending
|
| Jun 25, 2026 |
CVE-2026-54844
CheckView Automated Testing: Broken access control
CheckView Automated Testing is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 2.1.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
2.2.0 |
CVE7.5
NVDPending
|