External risk intelligence

AI Content Generator Marketing WordPress Plugin Unauthenticated Option Update Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-85118

The vulnerability exists in a WordPress plugin. WordPress sites are frequently deployed as internet-facing web applications. Because the affected AJAX actions are accessible to unauthenticated users, they are reachable by anyone with access to the public-facing web interface of the site.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security flaw has been identified in the AI Content Generator Marketing WordPress plugin, impacting how website options are managed. This vulnerability could allow unauthorized users to alter or remove critical site settings, potentially leading to a loss of administrative control over a WordPress site. The primary concern is to confirm if this plugin is in use and assess any exposure.

  • Unauthenticated users can change site settings.
  • Gaining admin access can disrupt site operations.
  • Confirm usage and assess exposure to WordPress sites.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted requests to the website's backend. Since the vulnerable component doesn't properly check user permissions for certain actions, an unauthenticated user can manipulate website settings. This manipulation could lead to an attacker gaining administrative control over the WordPress site.

  • No user authentication required.
  • Unauthenticated AJAX actions.
  • Can lead to administrator access.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated users could modify or delete arbitrary WordPress options through specific AJAX actions, potentially leading to unauthorized administrator access and control over the website. This could impact the site's content, functionality, and overall integrity when the plugin is active and these actions are not properly protected.

  • WordPress site options and administrative access.
  • Via unauthenticated AJAX actions.
  • Complete site compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the AI Content Generator Marketing WordPress plugin impacts websites using it, placing responsibility on the Application Owners or Web Administrators who manage WordPress instances. The initial step is to inventory all WordPress sites, identify those with the affected plugin, and assess their exposure. Once identified and prioritized, a remediation plan should be developed, potentially involving vendor coordination or temporary mitigation if direct patching is not immediately feasible.

  • Application owners must confirm plugin usage.
  • Verify plugin reachability and business criticality.
  • Plan remediation based on identified risks.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the AI Content Generator Marketing plugin?

It is a WordPress extension designed to automate or assist in creating website content. It integrates directly into the WordPress dashboard, allowing users to manage site features. By extending the core platform, it adds specialized functionality, but like any plugin, it introduces additional code that must be properly secured to maintain the integrity of the host application.

What does CWE-269 mean for CVE-2026-85118?

CWE-269 is the weakness class for Improper Privilege Management. In the context of this CVE, it means the plugin fails to verify if a user has the appropriate authority before allowing them to perform sensitive tasks. Because these checks are missing, the plugin treats requests from random visitors with the same level of trust as those from an administrator.

How does an attacker trigger this vulnerability?

An attacker triggers the flaw by sending a crafted request to specific background processing functions known as AJAX actions. These actions are intended for legitimate internal use but lack required permission gates. The bug is only triggered when these specific unprotected functions are called; simply visiting the site's public-facing pages normally does not invoke these risky commands.

Is my site at risk according to Halo Surface Signal?

Halo Surface Signal identifies that this vulnerability is highly relevant because WordPress sites are typically internet-facing web applications. Since the problematic AJAX actions are reachable by any visitor via the public web interface, an attacker does not need special internal network access to attempt to exploit these settings.

What should I do if I use this plugin?

First, perform an inventory to confirm if the plugin is installed on your WordPress instances. Once identified, evaluate the criticality of those sites. Since the flaw allows unauthorized changes to core settings, prioritize these sites for remediation, which may involve disabling the plugin, seeking an update from the vendor, or implementing access restrictions.

References