CVE-2026-14526 (matched: wordpress)

  • Saturday, 8th August, 2026
  • 16:04pm

A security vulnerability tracked as CVE-2026-14526 has been found in the AI Copilot – Content Generator plugin for WordPress, which impacts all versions up to and including 1.5.6. The flaw allows unauthenticated attackers (people who do not have a login or authorized access to your site) to create a new full administrator-level account on your WordPress site, giving them complete control over your entire website.

This exploit is only possible if your site displays the plugin's [aiwu-form] shortcode or public chatbot on any public-facing page. When these features are active, a secret security check value that is supposed to block unauthorized actions is exposed in public code loaded on those pages, making that security check completely useless.

To carry out the attack, bad actors can save and run a malicious workflow that uses the plugin's user creation tool to set the new account to administrator level, resulting in full site takeover.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14526

« Back