CVE-2026-14526 (matched: wordpress)

  • Monday, 10th August, 2026
  • 10:05am

A security vulnerability has been identified in the WordPress plugin "AI Copilot – Content Generator", which impacts all versions up to and including 1.5.6. The flaw is an authorization bypass, meaning attackers who do not have any existing login access to your site can exploit it to create a new full administrator-level account for your website. If successful, this would let the attacker take complete control of your site. This exploit works on any site where the plugin's [aiwu-form] shortcode or public chatbot is displayed on a public-facing page, because the plugin's required security check token is exposed in the public code of these pages, making the standard access control check useless.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14526

« Back