Impact
The AI Website Builder WordPress plugin (GitHub build) 1.0.0 lacks any authorization or nonce verification on its REST API routes, enabling attackers to perform actions such as installing and activating plugins, importing content, writing files into the uploads directory, and deleting site content without authentication. If the server serves PHP files from the uploads directory, the ability to write a file of the attacker's choice equates to remote code execution, allowing complete compromise of the web application and potentially the hosting server.
Affected Systems
WordPress sites using the AI Website Builder plugin (GitHub build) version 1.0.0 are impacted. This vulnerability does not affect other plugin versions or different WordPress components.
Risk and Exploitability
The vulnerability scores a CVSS of 9.8, indicating a high severity. No EPSS score is available, and it is not listed in the KEV catalog. The attack path is straightforward: an unauthenticated attacker can invoke unsecured REST endpoints to deliver malicious code or configuration. Successful exploitation can lead to full control over the compromised site, data loss, and further pivoting to other assets.
OpenCVE Enrichment