PT-2026-69186 · WordPress · Ai-Copilot-Content-Generator

·

CVE-2026-14526

·

Published

2026-08-08

·

Updated

2026-08-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AI Copilot – Content Generator versions prior to 1.5.7
Description An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Unauthenticated attackers can achieve full site takeover by creating a new administrator-level user account. This is accomplished by saving and executing a malicious workflow that includes a wp create user action node with the role variable set to administrator. The issue is exploitable on sites where the [aiwu-form] shortcode or a public chatbot is rendered on a frontend page, as the waic-nonce value is exposed in the publicly accessible JavaScript WAIC DATA.waicNonce, making the nonce check ineffective.
Recommendations Update AI Copilot – Content Generator to a version later than 1.5.6.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14526

Affected Products

Ai-Copilot-Content-Generator