Executive brief
The AI Website Builder WordPress plugin (GitHub build) version 1.0.0 fails to check user permissions on its REST API endpoints, allowing attackers without any authentication to install malicious plugins, import content from external sources, write files to the site's uploads folder, and delete website content. This vulnerability can lead to complete website takeover and remote code execution if the hosting environment allows PHP execution from the uploads directory.
Technical details
The vulnerability is a missing authorization check (CWE-862) in the plugin's REST API routes. The vulnerable component fails to perform both authentication and nonce validation, allowing unauthenticated attackers to directly invoke sensitive operations. An attacker with network access to the REST API can install/activate arbitrary plugins and themes, write arbitrary files to the uploads directory (resulting in RCE on hosts serving PHP from that location), import content from attacker-controlled URLs, and delete site media. The attack requires no user interaction or authentication. No fixed version exists for the GitHub build (gw-website-builder-main); the official WordPress.org releases under the slug gw-ai-website-builder are patched with capability checks and are not affected.
Affected products
- AI Website Builder AI Website Builder (GitHub build) 1.0.0
Timeline
- 2026-09-02: disclosed
- 2026-09-04: advisory