Junglewise Threat Intelligence

CVE-2026-17153: SiteGround AI Agent authorization bypass in media upload

CVE-2026-17153 · Severity: medium · CVSS 5.3 · Published 2026-08-20

Executive brief

The AI Agent plugin for WordPress, used by website administrators to manage AI-powered features, contains a flaw that allows users with basic editor permissions (Contributors) to upload images to the WordPress media library—an action normally restricted to higher-privileged users. An attacker with a low-level editor account could exploit this to inject malicious media files, potentially compromising site content or introducing malware.

Technical details

The vulnerability is an authorization bypass in the AI Agent plugin affecting versions up to 1.2.7. The vulnerable endpoint fails to check the upload_files capability when processing file uploads; instead, it only validates the sg_ai_studio_gutenberg_nonce security token, which is issued to any user with block editor access (including Contributors). An authenticated attacker with Contributor-level or higher privileges can satisfy both the nonce and permission checks despite lacking upload_files capability, allowing unauthorized media library uploads. The root cause is the absence of a capability check before file upload processing. No authentication is required for unauthenticated exploitation if the nonce can be obtained, though the advisory indicates authenticated Contributor access is the primary attack vector. A patch addressing this authorization bypass has likely been released in version 1.2.8 or later.

Affected products

  • SiteGround AI Agent up to 1.2.7

Timeline

  • 2026-08-20: disclosed

References