A security vulnerability has been found in the AI Copilot – Content Generator plugin for WordPress, affecting all versions up to and including 1.5.6. The plugin fails to properly confirm that a user is allowed to perform certain actions, creating an authorization bypass flaw.
This flaw lets unauthenticated attackers (people who do not have an account on your site) create a new full administrator account for your WordPress site, giving them complete control of your site. They can exploit this by running a malicious workflow that includes a command to create a user with administrator privileges.
The attack only works on sites where the [aiwu-form] shortcode or the plugin's public chatbot appears on a public-facing page. On these pages, a security check value is accidentally exposed in the page's public code, which makes the permission check meant to block this attack useless.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14526