Description
Missing Authorization vulnerability in PenciDesign Penci AI SmartContent Creator penci-ai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Penci AI SmartContent Creator: from n/a through <= 2.0.
Published: 2026-02-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized content modification or creation due to missing authorization checks
Action: Upgrade
AI Analysis

Impact

The Penci AI SmartContent Creator plugin contains a missing authorization check, which results in a broken access control vulnerability. An attacker who can reach the plugin’s endpoints may create new posts, modify or delete existing content, or execute other privileged actions without proper permission. This flaw aligns with CWE-862, indicating that the application fails to verify a user’s entitlement before allowing access to sensitive operations. The CVSS base score of 4.3 reflects moderate impact, with potential loss of data integrity or availability if the vulnerability is abused. Based on the description, it is inferred that the attacker may need to be a logged‑in WordPress user, although the plugin’s endpoints may be reachable without authentication if not properly protected.

Affected Systems

All WordPress installations that use the Penci AI SmartContent Creator plugin version 2.0 or earlier are affected. This includes any site that has installed the plugin from the first public release up to the 2.0 release; versions later than 2.0 are not known to be vulnerable.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity, and the EPSS probability of less than 1% suggests that the overall likelihood of exploitation is low on a national scale. The vulnerability is not listed in the CISA KEV catalog. Attackers are likely to target sites that use a recent version of WordPress with the plugin active, especially if the plugin’s endpoints are exposed to unauthenticated users. If authentication is required, an attacker would need to compromise or guess a legitimate WordPress user account with sufficient role privileges.

Generated by OpenCVE AI on April 16, 2026 at 06:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Penci AI SmartContent Creator to a version newer than 2.0 as soon as the vendor releases a patch.
  • If an upgrade cannot be performed immediately, restrict the plugin’s functionality to administrators by adjusting WordPress role permissions or using a capability‑control plugin.
  • Consider disabling or uninstalling the plugin until a patched version is available, especially if the site hosts sensitive content.
  • As an additional temporary safeguard, block the plugin’s public endpoints via a web‑application firewall or access‑control rules if possible.

Generated by OpenCVE AI on April 16, 2026 at 06:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 21 Feb 2026 08:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Feb 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Fri, 20 Feb 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Pencidesign
Pencidesign penci Ai Smartcontent Creator
Wordpress
Wordpress wordpress
Vendors & Products Pencidesign
Pencidesign penci Ai Smartcontent Creator
Wordpress
Wordpress wordpress

Thu, 19 Feb 2026 08:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in PenciDesign Penci AI SmartContent Creator penci-ai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Penci AI SmartContent Creator: from n/a through <= 2.0.
Title WordPress Penci AI SmartContent Creator plugin <= 2.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Pencidesign Penci Ai Smartcontent Creator
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:15:00.531Z

Reserved: 2026-02-17T13:23:30.505Z

Link: CVE-2026-27055

cve-icon Vulnrichment

Updated: 2026-02-20T17:33:50.497Z

cve-icon NVD

Status : Deferred

Published: 2026-02-19T09:16:26.673

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-27055

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T06:30:06Z

Weaknesses