PT-2026-60726 · WordPress · Copilot-Api

·

CVE-2026-9810

·

Published

2026-06-26

·

Updated

2026-07-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AI Copilot WordPress plugin versions prior to 1.5.4
Description The plugin fails to bind OAuth access tokens to a specific WordPress user. Consequently, the system accepts any valid token as an administrator session. This allows unauthenticated attackers who complete the public OAuth flow to execute privileged MCP tools with administrator privileges, enabling actions such as arbitrary user creation and role escalation.
Recommendations Update the AI Copilot WordPress plugin to version 1.5.4 or later.

Exploit

Fix

DoS

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9810

Affected Products

Copilot-Api