CVE-2026-14526 (matched: wordpress)

  • Saturday, 8th August, 2026
  • 10:04am

A security flaw has been found in the AI Copilot – Content Generator plugin for WordPress, affecting all versions up to and including 1.5.6. The plugin does not properly confirm that a user is allowed to perform sensitive actions, creating an opening for unauthorized access to your site.

If your site uses this plugin and displays either the [aiwu-form] shortcode or the plugin’s public chatbot on a public-facing page, unauthenticated attackers (people who do not have existing login access to your site) can exploit this issue. A security check the plugin uses is accidentally exposed in public site code, so attackers can bypass it to run a malicious workflow that creates a new full administrator account for your site. Gaining this level of access would let an attacker take complete control of your website.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14526

« Back