CRITICAL 9.8 CVE-2026-85118 Published 11 Oct 2026

WordPress AI Content Generator Marketing Plugin Privilege Escalation Vulnerability

Worried this affects your website?

The AI Content Generator Marketing WordPress plugin through 1.0.0 contains a missing authorization vulnerability in some of its AJAX actions.

The plugin does not enforce a nonce or capability check, allowing unauthenticated users to update and delete arbitrary WordPress options.

  • Affected versions: through 1.0.0
  • Impact: unauthenticated users can gain administrator access to the site.

Reference: CVE-2026-85118 on NVD

← Back to Security News