Unrated severityNVD Advisory· Published Oct 11, 2026
CVE-2026-85118
CVE-2026-85118
Description
The AI Content Generator Marketing WordPress plugin through 1.0.0 does not enforce a nonce or capability check on some of its AJAX actions, allowing unauthenticated users to update and delete arbitrary WordPress options, which can be used to gain administrator access to the site.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <=1.0.0
- Range: <=1.0.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.