CVE-2026-17153: The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi
Summary
The AI Agent by SiteGround plugin for WordPress has an authorization bypass vulnerability (a security flaw where access controls fail to properly check user permissions) in all versions up to 1.2.7 that allows unauthenticated attackers to upload images to the WordPress media library. The plugin fails to verify that users have the upload_files capability (a permission level normally restricted to certain user roles), and because the security token called sg_ai_studio_gutenberg_nonce is given to any user with block editor access, even Contributors can exploit this to upload files they shouldn't be able to.
Vulnerability Details
5.3(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
network
low
none
none
August 20, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-17153
First tracked: August 20, 2026 at 08:07 AM
Classified by LLM (prompt v3) · confidence: 75%