What happened
WPScan published CVE-2026-85118 (published 2026-10-11, CVSS 9.8 critical) for the AI Content Generator Marketing plugin ≤ 1.0.0: AJAX actions lack nonce and capability enforcement, enabling unauthenticated modification/deletion of arbitrary WordPress options and administrator-level takeover. Verified against NVD REST API (automatable=yes per CISA SSVC).
Why it matters
AI content-generation plugins are a growing attack surface on WordPress: an unauthenticated critical flaw in one gives full site control, and compromised WordPress hosts are frequently used to serve malicious content or pivot to the wider AI/marketing tooling the plugin integrates with.
Attack vector
Unauthenticated AJAX actions in the plugin lack nonce/capability checks (CWE-269 improper privilege management), so a remote attacker can update/delete arbitrary WordPress options to plant an admin account or otherwise take over the site. CISA SSVC marks it automatable with total technical impact.
Affected systems
AI Content Generator Marketing WordPress plugin through 1.0.0
Mitigation
Disable or update the plugin per the vendor; WPScan reference: https://wpscan.com/vulnerability/ba76e169-6c2a-489e-99df-a1c5d4aef24e/