Executive brief
The GW AI Website Builder plugin for WordPress, which helps users create websites using artificial intelligence, contains a security flaw that allows low-level users to disrupt its operation. An attacker with basic login credentials, such as a subscriber, can disconnect the plugin from its primary service, GravityWrite. This could lead to a loss of functionality and require administrative intervention to restore the connection.
Technical details
The GW AI Website Builder plugin for WordPress suffers from a missing authorization vulnerability (CWE-862) within the gwaiwebu_gravitywrite_disconnect_handler() function. The function fails to implement a capability check, allowing any authenticated user with at least Subscriber-level privileges to trigger the 'gwaiwebu_gravitywrite_disconnect' AJAX action. An attacker can exploit this to disconnect the plugin from the GravityWrite service, leading to unauthorized modification of the plugin's configuration state. The issue is present in all versions up to and including 1.0.1. A patch has been released in subsequent versions.
Affected products
- nandhiniwp GW AI Website Builder up to, and including, 1.0.1
Timeline
- 2026-07-10: advisory: NVD published the CVE record based on Wordfence data.
- 2026-07-10: disclosed
References
- https://plugins.trac.wordpress.org/browser/gw-ai-website-builder/tags/1.0.1/API/api-functions.php
- https://plugins.trac.wordpress.org/browser/gw-ai-website-builder/tags/1.0.1/API/api-functions.php
- https://plugins.trac.wordpress.org/browser/gw-ai-website-builder/trunk/API/api-functions.php
- https://plugins.trac.wordpress.org/browser/gw-ai-website-builder/trunk/API/api-functions.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3481065%40gw-ai-website-builder&new=3481065%40gw-ai-website-builder
- https://www.wordfence.com/threat-intel/vulnerabilities/id/49405ba1-b0fd-429b-a30a-95c8d3f26545?source=cve