Hugo | DevOps | Cybersecurity 🇱🇻[verified]@HugoValtersDisclosure
A critical authentication bypass (CVE‑2026‑14526) in the AI Copilot WordPress plugin lets unauthenticated users create admin accounts. The plugin remains unpatched; users are advised to disable it immediately.
CyberSignal | Cybersecurity News[verified]@XQOPTRXDisclosure
The tweet discloses CVE-2026-14526, an authorization bypass in AI Copilot WordPress plugin that lets unauthenticated attackers create admin accounts and take over the site.
CVE@CVEnewDisclosure
The text announces that CVE-2026-14526 affects the AI Copilot – Content Generator WordPress plugin by enabling an authorization bypass in all versions up to 1.5.6, without providing any PoC, exploit, patch, or evidence of active exploitation.
Infoflowcloud@infoflowcloudDisclosure
A new authorization bypass vulnerability (CVE‑2026‑14526) has been disclosed for the AI Copilot – Content Generator WordPress plugin, affecting all versions up to 1.5.6.
ThreatAft@ThreatAftPatch
The message alerts to two critical Dell VSI/AI Copilot CVEs, highlights their severity, and immediately urges patching, with no evidence of active exploitation or PoC sharing.
Haru🐿️情報セキュリティ担当🐿️@Harus0313Patch
The post warns that sites using ai‑copilot‑content‑generator v1.5.6 or lower have an authentication bypass that lets attackers create new admin users, and urges an immediate upgrade.