CVE-2026-82923
Received Received - Intake

Unauthenticated Plugin Installation in AI Website Builder

Vulnerability report for CVE-2026-82923, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: WPScan

Description

The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their control, write a file of their choosing into the uploads directory, and delete site content and media. On a host that serves PHP from the uploads directory, that file write is remote code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ai_website_builder wordpress_plugin to 1.0.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the AI Website Builder WordPress plugin (GitHub build) version 1.0.0. It lacks authorization and nonce checks on its REST API routes, allowing unauthenticated attackers to perform actions like installing plugins, importing malicious content, writing arbitrary files to the uploads directory, and deleting site content. If PHP is served from the uploads directory, the file write can lead to remote code execution.

Detection Guidance

Check if the AI Website Builder plugin (GitHub build) version 1.0.0 is installed by looking for the 'gw-website-builder-main' directory in your WordPress plugins folder. Inspect REST API routes for missing authorization or nonce checks. Look for unexpected files in the uploads directory or must-use plugins that were not manually installed.

Impact Analysis

Attackers could exploit this to take full control of your WordPress site, install malware, steal data, or deface your website. Even after removing the plugin, a persistent must-use plugin may remain, allowing attackers to maintain access by planting malicious scripts.

Compliance Impact

This vulnerability could lead to data breaches, unauthorized access, or data loss, which may violate GDPR, HIPAA, or other regulations. Compliance requires protecting user data and ensuring system integrity, which this flaw undermines.

Mitigation Strategies

Immediately remove the AI Website Builder plugin (GitHub build) version 1.0.0. After removal, manually delete the must-use plugin file created during activation and clear the option holding the script URL from the database to prevent persistent access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82923. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart