CVE-2026-14526 (matched: wordpress)

  • Sunday, 9th August, 2026
  • 16:04pm

A security flaw has been found in the AI Copilot – Content Generator plugin for WordPress, impacting all versions up to and including 1.5.6. The issue is an authorization bypass, meaning the plugin does not properly check if a user is allowed to perform specific actions on your site.

This vulnerability only affects sites that have either the [aiwu-form] shortcode or the plugin’s public chatbot displayed on any public-facing page. On these sites, unauthenticated attackers (people who do not have a login account for your site) can exploit the flaw, as the plugin’s permission check is rendered useless: the security code it relies on is accidentally exposed in public, viewable website code when these features are active.

Successful exploitation lets attackers create a new full administrator account for your site, which would give them complete control over your entire website, including access to all content, user data, and site settings.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14526

« Back