Authorization Bypass in AI Copilot – Content Generator Plugin for WordPress
CVE-2026-14526

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
8 August 2026

What is CVE-2026-14526?

The AI Copilot – Content Generator plugin for WordPress allows unauthenticated attackers to create administrator-level user accounts. This occurs due to improper authorization checks, enabling malicious actors to execute a harmful workflow with a wp_create_user action node. The vulnerability is present in all versions up to and including 1.5.6, and it becomes exploitable on sites displaying the [aiwu-form] shortcode or public chatbots, as key nonce values are exposed in the site's JavaScript.

Affected Version(s)

AI Copilot – Content Generator 0 <= 1.5.6

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

d.v4n_s3c
.