A security flaw has been found in the "AI Copilot – Content Generator" plugin for WordPress, impacting all versions up to and including 1.5.6. The plugin does not properly verify that a user is authorized to carry out sensitive actions, which allows unauthenticated attackers (people who do not have a login for your site) to take full control of your WordPress website.
This vulnerability is only exploitable if your site uses the [aiwu-form] shortcode or displays the plugin's public chatbot feature on any public-facing page. When these features are active, a security check token that is supposed to block unauthorized actions is accidentally exposed in public site code, rendering the permission check useless.
If an attacker successfully exploits this flaw, they can create a new administrator-level account for your site. This grants them full access to modify your site's content, access private data, or completely take over your website.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14526