CVE-2026-85118
AI Content Generator Marketing <= 1.0.0 - Unauthenticated Privilege Escalation via Arbitrary Option Update and Deletion
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The AI Content Generator Marketing WordPress plugin through 1.0.0 does not enforce a nonce or capability check on some of its AJAX actions, allowing unauthenticated users to update and delete arbitrary WordPress options, which can be used to gain administrator access to the site.
| Vendor | unknown |
| Product | ai content generator marketing |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown ai content generator marketing
Be the first to know when new unknown vulnerabilities affecting unknown ai content generator marketing are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / AI Content Generator Marketing
0 โค 1.0.0
References
Credits
Enrico Marcolini - Claudio Marchesini - Dottor Marc WPScan