A security flaw has been identified in the AI Copilot – Content Generator plugin for WordPress, affecting all versions up to and including 1.5.6. The plugin fails to properly verify that a user is authorized to perform certain actions, which lets unauthenticated attackers (people not logged into your site) create a new full administrator-level account for your WordPress site. If this flaw is exploited, an attacker will gain complete control over your entire website, including access to all your content, user data, and site settings.
This vulnerability is only exploitable if your site has either the plugin’s [aiwu-form] shortcode, or its public chatbot feature, displayed on any page accessible to visitors. The broken authorization check means the plugin’s built-in security barrier for this action is non-functional, leaving no protection against unauthenticated users creating new admin accounts.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14526