CVE-2026-17153Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to upload images to the WordPress media library, bypassing the upload_files capability restriction that Contributors are normally subject to, as authenticated attackers with Contributor-level access or above can satisfy the endpoint's nonce and permission checks. The sg_ai_studio_gutenberg_nonce required by the endpoint is emitted to any user with block editor access — including Contributors — making the absent upload_files check the sole barrier to exploitation.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-20: 3Technical Details · 2026-08-20: 308-20
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-17153 The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to the plugin not prope… https://www.cve.org/CVERecord?id=CVE-2026-17153 ----- Traducción: CVE-2026-17153 El … https://infoflow.cloud`

    Post summary

    CVE-2026-17153 reveals an authorization bypass in SiteGround's AI Agent WordPress plugin versions up to 1.2.7, detailing the vulnerability but providing no PoC, exploit, or patch information.

    0000149
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-17153 The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to the plugin not prope… https://www.cve.org/CVERecord?id=CVE-2026-17153

    Post summary

    A WordPress plugin vulnerability (CVE-2026-17153) allowing authorization bypass in versions up to 1.2.7 has been disclosed, but no PoC, exploit, or patch details are provided in the text.

    000001.0K
    58.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-17153 AI Agent by SiteGround WordPress Plugin Authorization Bypass Allows Image Uploads https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-17153

    Post summary

    The entry announces CVE-2026-17153, an authorization bypass in SiteGround’s AI Agent WordPress plugin that permits unauthorized image uploads, with no mention of exploitation, PoC, or remediation.

    00000116
    4.1K followersView on X

Explore more