Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

AI Copilot WordPress plugin OAuth token binding vulnerability

The AI Copilot WordPress plugin before version 1.5.4 fails to bind OAuth access tokens to specific WordPress users, allowing unauthenticated attackers to complete a public OAuth flow and execute privileged MCP tools as an administrator, including arbitrary user creation and role escalation.

Disclosed 17 July 2026 · Record updated 13 September 2026

Impact

Unauthenticated attackers can execute privileged MCP tools as administrator, enabling arbitrary user creation and role escalation on affected WordPress installations.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-9810