CVE-2026-14526
Received Received - Intake

Authorization Bypass in AI Copilot WordPress Plugin

Vulnerability report for CVE-2026-14526, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-08

Last updated on: 2026-08-08

Assigner: Wordfence

Description

The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create a new administrator-level user account and achieve full site takeover by saving and executing a malicious workflow containing a wp_create_user action node specifying role=administrator. This vulnerability is exploitable by unauthenticated attackers on any site where the [aiwu-form] shortcode or public chatbot is rendered on a frontend page, as the waic-nonce value is emitted into publicly accessible JavaScript (WAIC_DATA.waicNonce) on those pages, rendering the nonce check a non-functional authorization barrier.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-08
Last Modified
2026-08-08
Generated
2026-08-08
AI Q&A
2026-08-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ai_copilot content_generator to 1.5.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The AI Copilot – Content Generator WordPress plugin up to version 1.5.6 has an authorization bypass flaw. It fails to verify user permissions properly, allowing unauthenticated attackers to create an administrator account by exploiting a malicious workflow with a wp_create_user action node. This is possible because the plugin exposes a nonce value in frontend JavaScript, making the authorization check ineffective.

Detection Guidance

Check WordPress sites using the AI Copilot – Content Generator plugin versions up to 1.5.6. Look for unauthorized admin user accounts in the WordPress dashboard under Users. Inspect frontend pages for the [aiwu-form] shortcode or public chatbot rendering WAIC_DATA.waicNonce in JavaScript.

Impact Analysis

Unauthenticated attackers can take over your WordPress site by creating an admin account. This grants full control over the site, including modifying content, installing malicious plugins, stealing data, or defacing the website. Sites using the [aiwu-form] shortcode or public chatbot are at risk.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR and HIPAA requirements for data protection and access control. A successful exploit may result in non-compliance, legal penalties, and reputational damage due to compromised user data.

Mitigation Strategies

Immediately update the AI Copilot – Content Generator plugin to the latest version. Remove any unauthorized administrator accounts found in WordPress. Disable the plugin if no update is available. Monitor user accounts for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14526. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart