← WordPress Vulnerabilities
WordPress security by component

AI Copilot – Content Generator

AI Copilot – Content Generator generates and assists with WordPress content using artificial intelligence within the editing workflow.

AI Copilot – Content Generator (ai-copilot-content-generator) is a WordPress plugin with 9 published CVE records in this archive. The latest tracked vulnerability was published Aug 08, 2026; the highest published CVSS base score is 9.8.

Plugin slug: ai-copilot-content-generator

CVE-2026-14526: AI Copilot public workflow actions let unauthenticated attackers create administrators

AI Copilot through 1.5.6 can expose its workflow nonce on a public [aiwu-form] form or chatbot. An unauthenticated attacker can reuse that nonce in a request to admin-ajax.php with pl=waic, reqType=ajax and mod=workflow, save a crafted workflow containing the wp_create_user operation with the administrator role, and then run it. The workflow reaches wp_insert_user() and creates an attacker-controlled administrator account. Version 1.5.8 hardens the workflow actions; WordPress.org does not offer a 1.5.7 release.

PublishedAug 08, 2026
Known safe version1.5.8
Published vulnerabilities for ai-copilot-content-generator
Safe version
Aug 08, 2026 CVE-2026-14526
AI Copilot public workflow actions let unauthenticated attackers create administrators
AI Copilot through 1.5.6 can expose its workflow nonce on a public [aiwu-form] form or chatbot. An unauthenticated attacker can reuse that nonce in a request to admin-ajax.php with pl=waic, reqType=ajax and mod=workflow, save a crafted workflow containing the wp_create_user operation with the administrator role, and then run it. The workflow reaches wp_insert_user() and creates an attacker-controlled administrator account. Version 1.5.8 hardens the workflow actions; WordPress.org does not offer a 1.5.7 release.
1.5.8
CVE9.8
NVDPending
Aug 06, 2026 CVE-2026-65507
AIWU through 1.5.6 permits unauthenticated privilege escalation
An unauthenticated visitor can cross an authorization boundary in AIWU 1.5.6 and earlier and obtain elevated WordPress privileges. The CNA does not identify the vulnerable endpoint or action, attacker-controlled parameter, authorization check that is missing or bypassed, or the role or capability ultimately obtained. Version 1.5.8 is recorded as unaffected; the status of 1.5.7 is not stated.
1.5.8
CVE9.8
NVDPending
Aug 05, 2026 CVE-2026-6639
AI Copilot task enumeration exposes OpenAI API keys and prompts
AI Copilot – Content Generator through 1.4.6 registers controller methods for unauthenticated AJAX access, omits getCurrentTaskResults() from getNoncedMethods(), and inherits an empty permission requirement. Task parameters created by features such as Bulk Post Generator are stored in the database, and an unauthenticated attacker can enumerate sequential task IDs to retrieve plaintext OpenAI API keys, prompts, keywords and model configuration. The CNA does not disclose the AJAX action or task-ID parameter name.
> 1.4.6
CVE7.5
NVDPending
Jul 23, 2026 CVE-2026-13009
AI Copilot – Content Generator: SQL injection
AI Copilot – Content Generator is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.5.4. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVDPending
Jul 13, 2026 CVE-2026-59515
AIWU: SQL injection
AIWU is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.5.4. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
1.5.5
CVE9.3
NVDPending
Jul 11, 2026 CVE-2026-6804
AI Copilot – Content Generator: A security weakness
AI Copilot – Content Generator is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.4.12. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.3
NVDPending
Jul 11, 2026 CVE-2026-6803
AI Copilot – Content Generator: A security weakness
AI Copilot – Content Generator is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.4.12. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.3
NVDPending
Jun 01, 2026 CVE-2026-48879
AIWU: Privilege escalation or authentication bypass
AIWU is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 1.4.17. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
1.4.19
CVE9.8
NVDPending
May 12, 2026 CVE-2026-2993
AI Chatbot & Workflow Automation by AIWU: SQL injection
AI Chatbot & Workflow Automation by AIWU is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.4.17. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE7.5
NVDPending