CVE-2026-17153
A vulnerability exists in the SiteGround AI Agent plugin for WordPress, affecting versions up to 1.2.7, where an attacker can upload images to the WordPress media library without proper authorization. This is due to the plugin's failure to verify user permissions, allowing unauthenticated attackers to bypass normal upload restrictions. Authenticated users with Contributor-level access or higher can also exploit this vulnerability by satisfying the necessary nonce and permission checks, which are not adequately enforced by the plugin. The vulnerability lies in the plugin's lack of a proper upload_files check.
Based on public CVE data (MITRE/NVD).