
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25391 is a Missing Authorization vulnerability in the WP Grids WP Wand WordPress plugin (slug: ai-content-generation) that allows authenticated attackers with low-level privileges to exploit incorrectly configured access control security levels. The vulnerability affects WP Wand versions from n/a through 1.3.07. It was published on February 19, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) (Feedly).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify that a requesting user has the necessary permissions before executing sensitive actions related to AI content generation. The attack vector is network-based, requires low privileges (authenticated user), no user interaction, and low attack complexity. Because authorization checks are absent or misconfigured, a low-privileged WordPress user (e.g., subscriber or contributor) can invoke restricted plugin functionality that should be limited to higher-privileged roles (Feedly).
Successful exploitation results in low integrity and low availability impacts, with no confidentiality impact. An authenticated attacker could abuse the plugin's AI content generation features beyond their intended permission level — for example, triggering unauthorized content creation or modification actions, or causing unintended resource consumption on the WordPress site. The scope is unchanged, meaning the impact is confined to the vulnerable component itself (Feedly).
The EPSS score for CVE-2026-25391 is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the wild at this time. No public proof-of-concept exploit code, active in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been identified for this vulnerability. Exploitation requires a valid low-privileged account on the target WordPress installation (Feedly).
ai-content-generation) version 1.3.07 or earlier, using tools like WPScan or by checking the plugin's readme.txt file at https://target.com/wp-content/plugins/ai-content-generation/readme.txt.wp-admin/admin-ajax.php with WP Wand-specific action parameters from low-privileged user accounts; unexpected REST API calls to WP Wand endpoints from subscriber or contributor accounts.Users should update the WP Wand plugin to a version beyond 1.3.07 that includes proper authorization checks, once a patched release is made available by WP Grids. In the interim, site administrators should consider deactivating the plugin if it is not critical to operations, or restricting site registration to prevent untrusted users from obtaining low-privileged accounts. Monitoring WordPress user activity logs for unexpected plugin interactions is also recommended (Feedly, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."