Junglewise Threat Intelligence

CVE-2026-9616: WordPress Generate Security.txt authorization bypass in AJAX actions

CVE-2026-9616 · Severity: medium · CVSS 4.3 · Published 2026-06-24

Executive brief

A security plugin for WordPress, which helps websites communicate their vulnerability reporting policies, contains a flaw that allows low-level users to interfere with its settings. An attacker with a basic account on the site could delete the website's security policy file or create unauthorized folders on the server. This could disrupt the site's security communications and potentially interfere with other server operations.

Technical details

The Generate Security.txt plugin for WordPress fails to implement proper authorization checks on specific AJAX actions. Specifically, the 'delete_securitytxt' and 'create_wellknown_folder' functions do not verify if the requesting user has administrative privileges. An authenticated attacker with subscriber-level permissions or higher can directly invoke these AJAX actions to delete the site's security.txt file from the filesystem or create a '.well-known' directory. This vulnerability stems from a lack of capability checks (e.g., current_user_can) within the affected administrative functions.

Affected products

  • WordPress Plugin Generate Security.txt Up to and including 1.0.12

Timeline

  • 2026-06-24: disclosed

References