CRITICAL
9.8 CVE-2026-82923 Published 4 Sept 2026
WordPress AI Website Builder Plugin Unauthenticated Access
Worried this affects one of your servers?
The AI Website Builder WordPress plugin (GitHub build) 1.0.0 is affected.
It lacks authorisation and nonce checks on its REST API routes, allowing unauthenticated attackers to:
- Install and activate plugins and themes
- Import content from a malicious URL
- Write a file to the uploads directory
- Delete site content and media
On hosts serving PHP from the uploads directory, the file write can lead to remote code execution.
Reference: CVE-2026-82923 on NVD
← Back to Security News