CVE-2026-25391
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-25391 is a Missing Authorization vulnerability in the WP Grids WP Wand WordPress plugin (slug: ai-content-generation) that allows authenticated attackers with low-level privileges to exploit incorrectly configured access control security levels. The vulnerability affects WP Wand versions from n/a through 1.3.07. It was published on February 19, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) (Feedly).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify that a requesting user has the necessary permissions before executing sensitive actions related to AI content generation. The attack vector is network-based, requires low privileges (authenticated user), no user interaction, and low attack complexity. Because authorization checks are absent or misconfigured, a low-privileged WordPress user (e.g., subscriber or contributor) can invoke restricted plugin functionality that should be limited to higher-privileged roles (Feedly).

Impact

Successful exploitation results in low integrity and low availability impacts, with no confidentiality impact. An authenticated attacker could abuse the plugin's AI content generation features beyond their intended permission level — for example, triggering unauthorized content creation or modification actions, or causing unintended resource consumption on the WordPress site. The scope is unchanged, meaning the impact is confined to the vulnerable component itself (Feedly).

Exploitability

The EPSS score for CVE-2026-25391 is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the wild at this time. No public proof-of-concept exploit code, active in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been identified for this vulnerability. Exploitation requires a valid low-privileged account on the target WordPress installation (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WP Wand plugin (slug: ai-content-generation) version 1.3.07 or earlier, using tools like WPScan or by checking the plugin's readme.txt file at https://target.com/wp-content/plugins/ai-content-generation/readme.txt.
  2. Obtain low-privileged account: Register or obtain credentials for a low-privileged WordPress account (e.g., subscriber role) on the target site.
  3. Identify unprotected AJAX/REST endpoints: Enumerate the plugin's registered WordPress AJAX actions or REST API endpoints that lack proper capability checks, typically found by reviewing the plugin's source code or by intercepting authenticated requests.
  4. Send unauthorized request: Craft and send an authenticated HTTP request (with valid nonce and session cookies) to the identified unprotected endpoint, invoking a restricted action such as triggering AI content generation or modifying plugin settings.
  5. Achieve objective: Observe that the action executes successfully despite the user lacking the required permissions, resulting in unauthorized content manipulation or resource consumption (Feedly).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated POST requests to wp-admin/admin-ajax.php with WP Wand-specific action parameters from low-privileged user accounts; unexpected REST API calls to WP Wand endpoints from subscriber or contributor accounts.
  • File System: Unexpected or unauthorized AI-generated content appearing in posts/pages not created by higher-privileged users.
  • Process/Application: Unusual spikes in AI content generation API usage or quota consumption not attributable to authorized editorial activity.

Mitigation and workarounds

Users should update the WP Wand plugin to a version beyond 1.3.07 that includes proper authorization checks, once a patched release is made available by WP Grids. In the interim, site administrators should consider deactivating the plugin if it is not critical to operations, or restricting site registration to prevent untrusted users from obtaining low-privileged accounts. Monitoring WordPress user activity logs for unexpected plugin interactions is also recommended (Feedly, Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-83547MEDIUM6.8
  • xpro-elementor-addons
NoYesSep 02, 2026
CVE-2026-82884MEDIUM6.8
  • all-in-one-seo-pack
NoYesSep 02, 2026
CVE-2026-8151MEDIUM5.4
  • simple-membership-mailchimp-integration
NoYesSep 02, 2026
CVE-2026-83533MEDIUM5.3
  • wp-express-checkout
NoYesSep 02, 2026
CVE-2026-81571MEDIUM4.8
  • brave-popup-builder
NoYesSep 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management