Vulnerability  ·  2026-10-12

AI Content Generator Marketing WordPress plugin: unauthenticated arbitrary options update/delete → admin takeover (CVSS 9.8)

VulnerabilityHigh impactGlobalCVE-2026-85118
WPScan published CVE-2026-85118 (published 2026-10-11, CVSS 9.8 critical) for the AI Content Generator Marketing plugin ≤ 1.0.0: AJAX actions lack nonce and capability enforcement, enabling unauthenticated modification/deletion of arbitrary WordPress options and administrator-level takeover. Verified against NVD REST API (automatable=yes per CISA SSVC).
AI content-generation plugins are a growing attack surface on WordPress: an unauthenticated critical flaw in one gives full site control, and compromised WordPress hosts are frequently used to serve malicious content or pivot to the wider AI/marketing tooling the plugin integrates with.
Unauthenticated AJAX actions in the plugin lack nonce/capability checks (CWE-269 improper privilege management), so a remote attacker can update/delete arbitrary WordPress options to plant an admin account or otherwise take over the site. CISA SSVC marks it automatable with total technical impact.
AI Content Generator Marketing WordPress plugin through 1.0.0
Disable or update the plugin per the vendor; WPScan reference: https://wpscan.com/vulnerability/ba76e169-6c2a-489e-99df-a1c5d4aef24e/
NVD CVE-2026-85118WPScan advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →