CVE · Medium

CVE-2026-17153 — AI Agent by SiteGround [sg-ai-studio] < 1.2.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-17153 AI Agent by SiteGround [sg-ai-studio] < 1.2.8 Missing Authorization Medium 5.3 < 1.2.8 1.2.8 2026-08-20

CVE-2026-17153

A vulnerability exists in the SiteGround AI Agent plugin for WordPress, affecting versions up to 1.2.7, where an attacker can upload images to the WordPress media library without proper authorization. This is due to the plugin's failure to verify user permissions, allowing unauthenticated attackers to bypass normal upload restrictions. Authenticated users with Contributor-level access or higher can also exploit this vulnerability by satisfying the necessary nonce and permission checks, which are not adequately enforced by the plugin. The vulnerability lies in the plugin's lack of a proper upload_files check.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.