A security vulnerability tracked as CVE-2026-14526 affects the AI Copilot – Content Generator plugin for WordPress, impacting all versions up to and including 1.5.6. The plugin does not properly verify that a user is authorized to perform actions within it, creating an authorization bypass flaw.
This flaw makes it possible for unauthenticated attackers (people who are not logged into your website at all) to create a new full administrator-level account for your site by executing a malicious pre-defined workflow in the plugin. Gaining administrator access gives an attacker full control over your entire website.
This vulnerability only poses a risk if your site uses the plugin's [aiwu-form] shortcode or public chatbot feature on any public-facing page. On those pages, a security token meant to block unauthorized access is exposed in publicly accessible site code, which renders the existing authorization check useless.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14526