Sensitive Information Exposure in AI Chatbot & Workflow Automation Plugin for WordPress
CVE-2026-6639
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-6639?
The AI Chatbot & Workflow Automation plugin for WordPress presents a vulnerability that allows unauthenticated attackers to exploit the getCurrentTaskResults() method, which is accessible without any authentication or authorization. This flaw occurs as the method is not included in the required permissions check and allows the retrieval of sensitive configuration data, such as OpenAI API keys and other task parameters. This data is stored in a database and can be returned in JSON format, making it easy for attackers to enumerate task IDs and access critical information, posing a significant risk to site security.
Affected Version(s)
AI Copilot β Content Generator 0 <= 1.4.6