PT-2026-60726 · WordPress · Copilot-Api
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AI Copilot WordPress plugin versions prior to 1.5.4
Description
The plugin fails to bind OAuth access tokens to a specific WordPress user. Consequently, the system accepts any valid token as an administrator session. This allows unauthenticated attackers who complete the public OAuth flow to execute privileged MCP tools with administrator privileges, enabling actions such as arbitrary user creation and role escalation.
Recommendations
Update the AI Copilot WordPress plugin to version 1.5.4 or later.
Exploit
Fix
DoS
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Copilot-Api