{"data":{"id":"a3393ef6-8ebf-42e1-b9cf-55c0d09ec1c9","title":"CVE-2026-17153: The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi","summary":"The AI Agent by SiteGround plugin for WordPress has an authorization bypass vulnerability (a security flaw where access controls fail to properly check user permissions) in all versions up to 1.2.7 that allows unauthenticated attackers to upload images to the WordPress media library. The plugin fails to verify that users have the upload_files capability (a permission level normally restricted to certain user roles), and because the security token called sg_ai_studio_gutenberg_nonce is given to any user with block editor access, even Contributors can exploit this to upload files they shouldn't be able to.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-17153","publishedAt":"2026-08-20T06:16:58.230Z","cveId":"CVE-2026-17153","cweIds":["CWE-862"],"cvssScore":"5.3","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["SiteGround"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-20T06:16:58.230Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity"],"aiComponentTargeted":null,"llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":null}}