Impact
The AI Agent by SiteGround plugin fails to enforce the upload_files capability when a user invokes the /generate‑content REST endpoint. This missing check means that an attacker—whether unauthenticated or a Contributor—can upload arbitrary media files to the WordPress media library. The vulnerability permits image uploads that bypass normal permission restrictions, potentially allowing the introduction of malicious content or future exploitation. The weakness is an authorization bypass, identified as CWE‑862.
Affected Systems
All WordPress installations running the AI Agent by SiteGround plugin version 1.2.7 or earlier are affected. The vulnerability resides in the plugin’s REST API and can be triggered on any site that has the plugin enabled.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The exploit requires only knowledge of the REST endpoint; no special privileges or credentials are needed beyond those available to a Contributor. Because a nonce that is sent to any user with block editor access is required, an attacker can simulate it. The EPSS score is unavailable, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not currently widely exploited. Nevertheless, sites exposing the endpoint should consider the risk of unauthorized media uploads and mitigate promptly.
OpenCVE Enrichment