CVE-2026-17153
Received Received - Intake

Authorization Bypass in SiteGround AI Agent WordPress Plugin

Vulnerability report for CVE-2026-17153, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-20

Assigner: Wordfence

Description

The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to upload images to the WordPress media library, bypassing the upload_files capability restriction that Contributors are normally subject to, as authenticated attackers with Contributor-level access or above can satisfy the endpoint's nonce and permission checks. The sg_ai_studio_gutenberg_nonce required by the endpoint is emitted to any user with block editor access β€” including Contributors β€” making the absent upload_files check the sole barrier to exploitation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-20
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
siteground ai_agent to 1.2.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The AI Agent by SiteGround WordPress plugin up to version 1.2.7 has an authorization bypass flaw. It fails to properly verify user permissions before allowing actions. Unauthenticated attackers can exploit this to upload images to the WordPress media library. The vulnerability bypasses the upload_files capability restriction normally enforced for Contributors.

Detection Guidance

Check WordPress installations for the AI Agent by SiteGround plugin version 1.2.7 or lower. Look for unauthorized image uploads in the media library or suspicious activity from Contributor-level users.

Impact Analysis

Attackers could upload malicious files to your WordPress site, potentially leading to remote code execution or defacement. Even Contributors with limited access could exploit this to bypass restrictions and upload unauthorized content.

Compliance Impact

This vulnerability could lead to unauthorized file uploads, potentially violating data integrity and access control requirements in GDPR or HIPAA. Unauthorized uploads may expose sensitive data or introduce malware, risking compliance breaches.

Mitigation Strategies

Update the AI Agent by SiteGround plugin to the latest version. Remove the plugin if not needed. Review media library uploads for unauthorized files and restrict Contributor-level user permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17153. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart