CVE-2026-14526
wupsales · AI Copilot – Content Generator
An authorization bypass in the AI Copilot WordPress plugin allows unauthenticated attackers to create administrator accounts and achieve full site takeover.
Executive summary
An unauthenticated authorization bypass in the AI Copilot plugin for WordPress enables attackers to escalate privileges to administrator and fully compromise the site.
Vulnerability
The plugin fails to perform adequate capability checks on administrative actions. Unauthenticated attackers can leverage a publicly exposed nonce to execute workflows, including the creation of new administrator accounts.
Business impact
This vulnerability carries a CVSS score of 9.8, representing a critical risk to site integrity and security. An attacker who gains administrator access can install malicious plugins, exfiltrate user data, or use the site to distribute malware, leading to severe reputational damage and legal liability.
Remediation
Immediate Action: There is currently no patched version available. Deactivate and remove the AI Copilot – Content Generator plugin until a secure update is released by the vendor.
Proactive Monitoring: Audit the WordPress user database for any newly created administrator accounts that were not authorized by legitimate staff members.
Compensating Controls: Utilize a Web Application Firewall (WAF) to restrict access to the plugin's workflow controller endpoints and block requests containing malicious workflow payloads.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Because no patch currently exists, the only effective way to mitigate this risk is to deactivate the plugin immediately. Administrators should monitor the vendor's security advisory channels closely and only re-enable the plugin once a verified update confirms the vulnerability is resolved.