Authorization Bypass in AI Copilot β Content Generator Plugin for WordPress
CVE-2026-14526
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 August 2026
What is CVE-2026-14526?
The AI Copilot β Content Generator plugin for WordPress allows unauthenticated attackers to create administrator-level user accounts. This occurs due to improper authorization checks, enabling malicious actors to execute a harmful workflow with a wp_create_user action node. The vulnerability is present in all versions up to and including 1.5.6, and it becomes exploitable on sites displaying the [aiwu-form] shortcode or public chatbots, as key nonce values are exposed in the site's JavaScript.
Affected Version(s)
AI Copilot β Content Generator 0 <= 1.5.6