← Back to overview

CVE-2026-82923 affects the AI Website Builder WordPress plugin (GitHub build) version 1.0.0. The plugin fails to perform any authorization or nonce checks on its REST API routes, allowing unauthenticated attackers to perform a wide range of malicious actions. These include installing and activating arbitrary plugins and themes, importing content from attacker-controlled URLs, writing arbitrary files to the uploads directory, and deleting site content and media. On servers that execute PHP files from the uploads directory, the arbitrary file write capability constitutes remote code execution (RCE). The vulnerability is critical due to its unauthenticated nature and the potential for full site compromise. No authentication or security tokens are required to exploit this flaw.

Affected products

  • AI Website Builder WordPress Plugin 1.0.0

Related CVE's

  • CVE-2026-82923

Categories

  • Identity & Access
  • Web Technologies
  • Zero-Day Vulnerabilities