AI Website Builder (GitHub build) 1.0.0 - Unauthenticated RCE via Unprotected REST Routes
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.8epss 0.6%
exploitation probability
0.6%top 55% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their control, write a file of their choosing into the uploads directory, and delete site content and media. On a host that serves PHP from the uploads directory, that file write is remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · AI Website Builder (GitHub build)public PoCs found — 1
cve_referencewpscan.com/vulnerability/663e7004-1cca-4c0f-8d54-7298d40fe179/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.