CyberRota Analysis
AI-GeneratedThe GW AI Website Builder plugin for WordPress is susceptible to unauthorized data modification due to a missing capability check in the gwaiwebu_gravitywrite_disconnect_handler() function, affecting all versions up to 1.0.1. This vulnerability allows authenticated attackers with Subscriber-level access or higher to disconnect the plugin from GravityWrite through the 'gwaiwebu_gravitywrite_disconnect' AJAX action. WordPress site administrators using this plugin should prioritize applying updates to mitigate potential exploitation.
Original NVD Description
The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gwaiwebu_gravitywrite_disconnect_handler() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disconnect the plugin from GravityWrite via the 'gwaiwebu_gravitywrite_disconnect' AJAX action.