CVE-2026-14526 (matched: wordpress)

  • Saturday, 8th August, 2026
  • 22:04pm

A security vulnerability has been identified in the AI Copilot – Content Generator plugin for WordPress, impacting all versions up to and including 1.5.6. The plugin does not properly confirm that a user is authorized to carry out sensitive actions on your website.

If your site displays the plugin's [aiwu-form] shortcode or public chatbot on any publicly accessible page, an attacker with no existing login credentials for your site can exploit this flaw. They can execute a malicious workflow to create a new administrator-level user account, which grants them full control over your entire site, including all content, settings, and user data.

The flaw exists because the plugin's standard authorization check relies on a security token that is exposed in publicly accessible site code, rendering the check ineffective at blocking unauthorized actions.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14526

« Back