CVE-2026-82923
CRITICAL
NVD
CVSS Score
9.8
Severity
CRITICAL
Published
Sep 04, 2026
Vendor
unknown
Description
The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their control, write a file of their choosing into the uploads directory, and delete site content and media. On a host that serves PHP from the uploads directory, that file write is remote code execution.