Impact
The vulnerability resides in the AI Content Generator Marketing WordPress plugin up to version 1.0.0. Certain AJAX actions lack nonce verification and capability checks, allowing an attacker who is not logged in to modify or delete arbitrary WordPress options. By manipulating these options, an unauthenticated user can gain administrative control over the site, potentially installing additional malware or exfiltrating data.
Affected Systems
WordPress sites running the AI Content Generator Marketing plugin version 1.0.0 or earlier are affected. The vulnerability is specific to that plugin and does not extend to other WordPress core components or unrelated plugins.
Risk and Exploitability
Because no authentication is required to perform the vulnerable operations, the attack vector is straightforward: an attacker can send crafted AJAX requests directly to the site. The exploitation does not depend on additional user privileges or other environmental preconditions. The official CVSS score is 9.8, and the lack of controls and the ability to elevate privileges to administrator imply a critical severity. The vulnerability is not listed in the CISA KEV catalog, but it remains a serious security risk for affected installations.
OpenCVE Enrichment