CVE-2026-14526

wupsales · AI Copilot – Content Generator

An authorization bypass in the AI Copilot WordPress plugin allows unauthenticated attackers to create administrator accounts and achieve full site takeover.

Executive summary

An unauthenticated authorization bypass in the AI Copilot plugin for WordPress enables attackers to escalate privileges to administrator and fully compromise the site.

Vulnerability

The plugin fails to perform adequate capability checks on administrative actions. Unauthenticated attackers can leverage a publicly exposed nonce to execute workflows, including the creation of new administrator accounts.

Business impact

This vulnerability carries a CVSS score of 9.8, representing a critical risk to site integrity and security. An attacker who gains administrator access can install malicious plugins, exfiltrate user data, or use the site to distribute malware, leading to severe reputational damage and legal liability.

Remediation

Immediate Action: There is currently no patched version available. Deactivate and remove the AI Copilot – Content Generator plugin until a secure update is released by the vendor.

Proactive Monitoring: Audit the WordPress user database for any newly created administrator accounts that were not authorized by legitimate staff members.

Compensating Controls: Utilize a Web Application Firewall (WAF) to restrict access to the plugin's workflow controller endpoints and block requests containing malicious workflow payloads.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Because no patch currently exists, the only effective way to mitigate this risk is to deactivate the plugin immediately. Administrators should monitor the vendor's security advisory channels closely and only re-enable the plugin once a verified update confirms the vulnerability is resolved.