AI Copilot Content Generator WordPress Plugin Authorization Bypass
The AI Copilot – Content Generator WordPress plugin up to version 1.5.6 is vulnerable to authorization bypass, allowing unauthenticated attackers to create administrator accounts and achieve full site takeover by executing malicious workflows with exposed nonce values.
Disclosed 8 August 2026 · Record updated 13 September 2026
Impact
Unauthenticated attackers can create administrator-level user accounts and achieve full site takeover on any WordPress site with the plugin installed and the [aiwu-form] shortcode or public chatbot rendered on a frontend page.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-14526
