VYPR

GW AI Website Builder

by WordPress

CVEs (2)

  • CVE-2026-82923CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their control, write a file of…

  • CVE-2026-1946MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gwaiwebu_gravitywrite_disconnect_handler() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated…