{"api_version":"v1","generated_at":"2026-10-08T20:15:00+00:00","product":{"cve_count":2,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-john-michael-l-allier-create-11f0703ad97c","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/create","name":"Create","next_cursor":null,"observations":[{"affected":"Create: \u2264 2.6.0","affected_versions_present":true,"cve_id":"CVE-2026-65490","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-65490","fixed":"Update the WordPress Create plugin to the latest available version (at least 2.6.1).","last_modified":"2026-09-18T16:15:24.802Z","patch_url":"https://patchstack.com/database/wordpress/plugin/mediavine-create/vulnerability/wordpress-create-by-mediavine-plugin-2-5-3-sensitive-data-exposure-vulnerability?_s_id=cve","primary_source":"","published":"2026-07-23T11:18:58.080Z"},{"affected":"Create: \u2264 2.5.3","affected_versions_present":true,"cve_id":"CVE-2026-24552","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24552","fixed":"Update the WordPress Create plugin to the latest available version (at least 2.5.4).","last_modified":"2026-09-21T17:02:09.908Z","patch_url":"https://patchstack.com/database/wordpress/plugin/mediavine-create/vulnerability/wordpress-create-by-mediavine-plugin-2-5-3-sql-injection-vulnerability?_s_id=cve","primary_source":"","published":"2026-07-23T11:17:47.929Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"John-Michael L'Allier"}}
