Authorization Bypass in AI Copilot – Content Generator Plugin for WordPress
⚠️ CVE-Referenzen:
CVE-2026-14526
WordPress - Ai Copilot – Content Generator - CRITICAL - CVE-2026-14526.
The AI Copilot – Content Generator plugin for WordPress allows unauthenticated attackers to create administrator-level user accounts. This occurs due to improper authorization checks, enabling malicious actors to execute a harmful workflow with a wp_create_user action node. The vulnerability is present in all versions up to and including 1.5.6, and it becomes exploitable on sites displaying the [aiwu-form] shortcode or public chatbots, as key nonce values are exposed in the site's JavaScript.
Quelle: securityvulnerability.io