CRITICAL
9.8 CVE-2026-85118 Published 11 Oct 2026
WordPress AI Content Generator Marketing Plugin Privilege Escalation Vulnerability
Worried this affects your website?
The AI Content Generator Marketing WordPress plugin through 1.0.0 contains a missing authorization vulnerability in some of its AJAX actions.
The plugin does not enforce a nonce or capability check, allowing unauthenticated users to update and delete arbitrary WordPress options.
- Affected versions: through 1.0.0
- Impact: unauthenticated users can gain administrator access to the site.
Reference: CVE-2026-85118 on NVD
← Back to Security News