CVE-2026-14526Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create a new administrator-level user account and achieve full site takeover by saving and executing a malicious workflow containing a wp_create_user action node specifying role=administrator. This vulnerability is exploitable by unauthenticated attackers on any site where the [aiwu-form] shortcode or public chatbot is rendered on a frontend page, as the waic-nonce value is emitted into publicly accessible JavaScript (WAIC_DATA.waicNonce) on those pages, rendering the nonce check a non-functional authorization barrier.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 5 mentions (2026-08-08); latest day: 1
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-08-08: 5Mentions · 2026-08-09: 1Patch / Workaround · 2026-08-08: 2Patch / Workaround · 2026-08-09: 1Technical Details · 2026-08-08: 5Technical Details · 2026-08-09: 108-0808-09
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-085
Disclosure3Patch2
2026-08-091
Disclosure1
Full discourse6 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-14526 The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin n… https://www.cve.org/CVERecord?id=CVE-2026-14526

    Post summary

    The text announces that CVE-2026-14526 affects the AI Copilot – Content Generator WordPress plugin by enabling an authorization bypass in all versions up to 1.5.6, without providing any PoC, exploit, patch, or evidence of active exploitation.

    010101.8K
    57.9K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-14526 - Critical auth bypass in AI Copilot WordPress plugin. Unauthenticated attackers can create admin accounts and take over sites. CVSS 9.8. Unpatched. Disable plugin now. #CVE #WordPress #infosec https://www.valtersit.com/cve/CVE-2026-14526 #infosec #cybersecurity #CVE #Linux #infosec #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu

    Post summary

    A critical authentication bypass (CVE‑2026‑14526) in the AI Copilot WordPress plugin lets unauthenticated users create admin accounts. The plugin remains unpatched; users are advised to disable it immediately.

    0000060
    1.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-14526 The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin n… https://www.cve.org/CVERecord?id=CVE-2026-14526 ----- Traducción: CVE-2026-14526 El … http://infoflow.cloud`

    Post summary

    A new authorization bypass vulnerability (CVE‑2026‑14526) has been disclosed for the AI Copilot – Content Generator WordPress plugin, affecting all versions up to 1.5.6.

    0000031
    98 followersView on X
  • ThreatAft@ThreatAft
    Patch

    🚨 Dell VSI + AI Copilot: Two Critical CVEs CVE-2026-54489 (9.1) — Dell VSI info disclosure CVE-2026-14526 (9.8) — AI Copilot auth bypass Both unauthenticated. Patch NOW. → http://threataft.com/articles/dell-vsi-ai-copilot-cve-bundle #cybersecurity #infosec #VMware #WordPress #AIsecurity #ThreatIntel

    Post summary

    The message alerts to two critical Dell VSI/AI Copilot CVEs, highlights their severity, and immediately urges patching, with no evidence of active exploitation or PoC sharing.

    0000063
    36 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🚨 Critical WordPress AI plugin flaw allows admin takeover CVE-2026-14526 — CVSS 9.8 The AI Copilot – Content Generator WordPress plugin contains an authorization bypass affecting versions through 1.5.6. Under vulnerable configurations, an unauthenticated attacker can create an administrator account and take over the site. 🔎 Source: Wordfence / CVE disclosure #WordPress #CVE #AISecurity #WebSecurity #CyberSecurity

    Post summary

    The tweet discloses CVE-2026-14526, an authorization bypass in AI Copilot WordPress plugin that lets unauthenticated attackers create admin accounts and take over the site.

    0000037
    34 followersView on X
  • Haru🐿️情報セキュリティ担当🐿️@Harus0313
    Patch

    💀CVE-2026-14526☠️ Wordpressプラグインai-copilot-content-generator(1.5.6以下)を使っているサイトはすぐにバージョンアップを。認証バイパスの脆弱性があり、攻撃者が新しい管理者ユーザーを作成してサイトを乗っ取ることができます。攻撃の複雑性も低く、事前の認証がなくても攻撃が可能です。

    Post summary

    The post warns that sites using ai‑copilot‑content‑generator v1.5.6 or lower have an authentication bypass that lets attackers create new admin users, and urges an immediate upgrade.

    0000094
    424 followersView on X

Explore more