The AI Copilot – Content Generator WordPress plugin (versions up to 1.5.6) contains an authorization bypass vulnerability allowing unauthenticated attackers to create administrator accounts and fully take over affected sites. The flaw stems from a nonce value being exposed in publicly accessible JavaScript, rendering the plugin's authorization check ineffective on any page rendering the [aiwu-form] shortcode or public chatbot.
Updated Aug 9, 2026 · CVSS 9.8