Skip to main content
EPSS 0.3%top 79%

CVE-2026-18786: CWE-287 Improper Authentication in CheckView

0
High
Published: 08/10/2026 (08/10/2026, 06:00:19 UTC)
Source: CVE Database V5
Product: CheckView

Description

The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose URI merely contains a CheckView WordPress plugin before 2.3.2-specific string, making it possible for unauthenticated attackers to bypass the REST nonce check and perform any REST action available to a logged-in administrator, such as creating a new administrator account, via a crafted link an administrator is tricked into opening.

CVSS v3.1

Score 8.8high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected software

CheckView

Affected versions
>=2.0.29 <2.3.2

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 15:18:28 UTC

Technical Analysis

CVE-2026-18786 is an improper authentication vulnerability (CWE-287) in the CheckView WordPress plugin before version 2.3.2. The plugin's REST API authentication filter is improperly applied globally to any request URI containing a CheckView-specific string, causing it to unconditionally discard authentication errors. This enables unauthenticated attackers to bypass REST nonce verification and execute privileged REST API actions as if they were logged-in administrators. The vulnerability can be exploited by tricking an administrator into opening a maliciously crafted link, potentially allowing the attacker to create new administrator accounts or perform other high-privilege actions via the REST API.

Potential Impact

Successful exploitation allows unauthenticated attackers to bypass authentication controls and perform any REST API action available to administrators. This includes creating new administrator accounts, leading to full site compromise with complete confidentiality, integrity, and availability impact.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the REST API endpoints and avoid opening suspicious links. Monitor for updates from the CheckView plugin vendor regarding patches or official mitigations.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
WPScan
Date Reserved
2026-08-04T08:30:55.647Z
State
PUBLISHED

Threat ID: 6a7972b2bf8831d5392fb098

Added to database: 08/10/2026, 06:41:54 UTC

Last enriched: 08/17/2026, 15:18:28 UTC

Last updated: 09/22/2026, 10:19:34 UTC

Views: 153

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses