Skip to main content
CRITICAL

CVE-2026-82923

CVSS v3

9.8

CRITICAL

EPSS Score

0.8 %

exploit probability, as of 2026-09-28

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their control, write a file of their choosing into the uploads directory, and delete site content and media. On a host that serves PHP from the uploads directory, that file write is remote code execution.

Technical details

Published
2026-09-04
Last Modified
2026-09-04

Frequently asked questions

What is CVE-2026-82923?

The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their control, write a file of their choosing into the uploads directory, and delete site content and media. On a host that serves PHP from the uploads directory, that file write is remote code execution.

Is CVE-2026-82923 actively exploited?

Active exploitation of CVE-2026-82923 has not been confirmed. Its EPSS score was 0.8% on 2026-09-28, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-82923?

CVE-2026-82923 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2026-82923 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key