EUVD Vulnerability Catalog
EUVD-2026-70990
Severity: CRITICAL
Base Score: 9.8
CVSS Version: 3.1
Vulnerability Description
The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their control, write a file of their choosing into the uploads directory, and delete site content and media. On a host that serves PHP from the uploads directory, that file write is remote code execution.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
▪
Attack Vector (AV): Network
▪
Attack Complexity (AC): Low
▪
Privileges Required (PR): None
▪
User Interaction (UI): None
▪
Scope (S): Unchanged
▪
Confidentiality Impact (C): High
▪
Integrity Impact (I): High
▪
Availability Impact (A): High
Affected Vendors & Systems
Vendor
Unknown
References & Advisory Links
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
WPScan
EPSS Probability
0
Known Aliases
CVE-2026-82923
Published On
2026-09-04
Last Updated
2026-09-04