CVE-2026-85118 PUBLISHED

AI Content Generator Marketing <= 1.0.0 - Unauthenticated Privilege Escalation via Arbitrary Option Update and Deletion

Assigner: WPScan
Reserved: 03.09.2026 Published: 11.10.2026 Updated: 11.10.2026

The AI Content Generator Marketing WordPress plugin through 1.0.0 does not enforce a nonce or capability check on some of its AJAX actions, allowing unauthenticated users to update and delete arbitrary WordPress options, which can be used to gain administrator access to the site.

Product Status

Vendor Unknown
Product AI Content Generator Marketing
Versions Default: unknown
  • affected from 0 to 1.0.0 (incl.)

Credits

  • Enrico Marcolini - Claudio Marchesini - Dottor Marc finder
  • WPScan coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE