CRITICAL 9.8 CVE-2026-82923 Published 4 Sept 2026

WordPress AI Website Builder Plugin Unauthenticated Access

Worried this affects one of your servers?

The AI Website Builder WordPress plugin (GitHub build) 1.0.0 is affected.

It lacks authorisation and nonce checks on its REST API routes, allowing unauthenticated attackers to:

  • Install and activate plugins and themes
  • Import content from a malicious URL
  • Write a file to the uploads directory
  • Delete site content and media

On hosts serving PHP from the uploads directory, the file write can lead to remote code execution.

Reference: CVE-2026-82923 on NVD

← Back to Security News