Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-65490
John-Michael L'Allier Create — WordPress Create by Mediavine plugin <= 2.6.0 - Sensitive Data Exposure vulnerability
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U L N N 5.3 .0033 23.8 —
AFFECTED
Product Versions Fixed
Create unspecified 2.6.1
TIMELINE
Jul 22 Reserved by Patchstack
Jul 23 Published (CNA: Patchstack)
Sep 18 PATCH SHIPPED — CVE-2026-65490 (John-Michael L'Allier Create). Fixed in Create 2.6.1.
Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in John-Michael L'Allier Create mediavine-create allows Retrieve Embedded Sensitive Data.This issue affects Create: from n/a through 2.6.0.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| July 22, 2026 | Reserved | Reserved by Patchstack |
| July 23, 2026 | Published | Published (CNA: Patchstack) |
| September 18, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-65490 (John-Michael L'Allier Create). Fixed in Create 2.6.1. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| John-Michael L'Allier | Create | — | — | 2.6.1 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-65490 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.