Sceawere

Vulnerability Detail

CVE-2026-85118UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

AI Content Generator Option Modification

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
8h ago
Vendor
Unknown
Product
AI Content Generator Marketing
Attack Type
CWE-269 Improper Privilege Management
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The AI Content Generator Marketing WordPress plugin through 1.0.0 does not enforce a nonce or capability check on some of its AJAX actions, allowing unauthenticated users to update and delete arbitrary WordPress options, which can be used to gain administrator access to the site.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-11T07:17:25.900Z",
  "pubdate": "2026-10-11T07:17:25.900Z",
  "executiveSummary": "A critical vulnerability has been identified in the AI Content Generator Marketing WordPress plugin affecting all versions through 1.0.0. The flaw stems from missing access controls and lack of cryptographic request verification across specific AJAX action handlers exposed by the plugin. Specifically, the endpoints fail to enforce authorization capability checks or validate request nonces.\nThis architectural omission allows unauthenticated remote attackers to execute arbitrary AJAX actions without supplying valid session credentials or CSRF tokens. By invoking these unprotected endpoints, an attacker can directly modify or delete arbitrary entries within the WordPress options database table. The potential impact of this flaw is severe, as option manipulation in WordPress can be leveraged to achieve total site takeover, user privilege escalation, and full administrative compromise of the target application.",
  "technicalDetails": "The root cause of this security defect lies in the improper implementation of WordPress AJAX registration hooks within the AI Content Generator Marketing WordPress plugin through version 1.0.0. In WordPress development, endpoints exposed to unauthenticated users rely on the 'wp_ajax_nopriv_' hook architecture. When registering these actions, custom functions must explicitly implement role-based access control using functions such as current_user_can() to verify user permissions, alongside check_ajax_referer() or wp_verify_nonce() to ensure request integrity and origin authentication.\nIn the affected plugin, vulnerable callback functions tied to AJAX actions execute administrative operations—specifically updating and deleting site options—without performing these mandatory security checks. Because no capability validation is enforced, any HTTP request routed to '/wp-admin/admin-ajax.php' with the corresponding action parameter is processed under the authority of the backend handler, regardless of the requester's authentication state.\nThe attack flow proceeds sequentially: First, an unauthenticated threat actor issues a HTTP POST or GET request directed at the target site's AJAX endpoint, specifying the vulnerable action parameter associated with the AI Content Generator Marketing plugin. Second, the payload supplies arbitrary option keys and values corresponding to core WordPress configuration settings in the 'wp_options' table.\nUpon receiving the unverified request, the vulnerable plugin code invokes WordPress core database functions such as update_option() or delete_option() using the attacker-controlled input parameters. This allows the attacker to alter critical system configurations. For example, an attacker can modify the 'users_can_register' option to '1' and set the 'default_role' option to 'administrator'. Subsequently, the attacker registers a new account through the standard WordPress registration portal, which is automatically granted full administrator privileges.\nAlternatively, attackers can overwrite options like 'siteurl' or 'home' to redirect site traffic to malicious external domains, or delete essential system options to trigger application errors and cause persistent denial-of-service conditions. Exploitation requires no privileged access, user interaction, or specialized environment configurations, making this vulnerability highly critical."
}
CVE-2026-85118: AI Content Generator Option Modification (CRITICAL Severity, CVSS: 9.8) | Sceawere