Flagship disclosure · Highest severity
CheckView · CVE-2026-18786
Unauthenticated Administrator Account Creation via REST API Authentication Bypass
An unauthenticated request could bypass REST API authentication and create a full administrator account — a complete site takeover with no credentials required. Discovered in a local lab, reported through WPScan under coordinated disclosure, and resolved by the vendor before public release.
Access Unauthenticated Fixed in 2.3.2 Published 2026-08-07
Read the WPScan advisory