A security vulnerability tracked as CVE-2026-14526 has been found in the "AI Copilot – Content Generator" plugin for WordPress, affecting all versions up to and including 1.5.6. The plugin does not properly check if a user has permission to carry out sensitive actions, which makes it possible for attackers with no existing site login to create a new full administrator account on your site and take complete control of it.
This flaw can be exploited on any site where the plugin's [aiwu-form] shortcode or public chatbot is shown on a public-facing page. This is because the security token meant to block unauthorized requests is accidentally exposed in publicly accessible JavaScript code on those pages, making the built-in permission check completely useless.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14526