AI Agent by SiteGround WordPress plugin authorization bypass
The AI Agent by SiteGround WordPress plugin versions up to 1.2.7 are vulnerable to an authorization bypass that allows unauthenticated attackers to upload images to the media library by exploiting missing upload_files capability checks.
Disclosed 20 August 2026 · Record updated 13 September 2026
Impact
Unauthenticated attackers can bypass upload restrictions and upload images to WordPress media library; Contributors and higher-level authenticated users can also exploit the vulnerability.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-17153
