A security vulnerability has been identified in the AI Copilot – Content Generator plugin for WordPress, impacting all versions up to and including 1.5.6. The plugin does not properly confirm that a user is authorized to carry out sensitive actions on your website.
If your site displays the plugin's [aiwu-form] shortcode or public chatbot on any publicly accessible page, an attacker with no existing login credentials for your site can exploit this flaw. They can execute a malicious workflow to create a new administrator-level user account, which grants them full control over your entire site, including all content, settings, and user data.
The flaw exists because the plugin's standard authorization check relies on a security token that is exposed in publicly accessible site code, rendering the check ineffective at blocking unauthorized actions.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14526