Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

AI Agent by SiteGround WordPress plugin authorization bypass

The AI Agent by SiteGround WordPress plugin versions up to 1.2.7 are vulnerable to an authorization bypass that allows unauthenticated attackers to upload images to the media library by exploiting missing upload_files capability checks.

Disclosed 20 August 2026 · Record updated 13 September 2026

Impact

Unauthenticated attackers can bypass upload restrictions and upload images to WordPress media library; Contributors and higher-level authenticated users can also exploit the vulnerability.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-17153