AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow Route
critical
The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create a new administrator-l...
- CVSS:
- 9.8
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.8
- Disclosed:
- Aug 7, 2026
CVE-2026-14526 on NVD →
AI Chatbot & Workflow Automation by AIWU <= 1.4.6 - Missing Authorization to Unauthenticated Sensitive Information Exposure
high
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6. This is due to the `getCurrentTaskResults()` method in `modules/workspace/controller.php` being accessible without authentication or authorization checks. The me...
- CVSS:
- 7.5
- Affected:
- up to 1.4.6
- Fixed in:
- 1.4.19
- Disclosed:
- Aug 4, 2026
CVE-2026-6639 on NVD →
AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation
critical
The AI Copilot – Content Generator plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
- CVSS:
- 9.8
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.8
- Disclosed:
- Jul 28, 2026
CVE-2026-65507 on NVD →
AI Copilot <= 1.5.4 - Authenticated (Subscriber+) SQL Injection via 'order[0][dir]' Parameter
medium
The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for au...
- CVSS:
- 6.5
- Affected:
- up to 1.5.4
- Fixed in:
- 1.5.8
- Disclosed:
- Jul 22, 2026
CVE-2026-13009 on NVD →
AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Modification via 'publishTasks' and 'unpublishTasks' AJAX Actions
medium
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to publish draft Wor...
- CVSS:
- 5.3
- Affected:
- up to 1.4.12
- Fixed in:
- 1.5.4
- Disclosed:
- Jul 10, 2026
CVE-2026-6804 on NVD →
AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via AJAX Actions 'removeGroup' and 'clear'
medium
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12. This is due to missing capability checks and nonce verification on AJAX actions registered under both wp_ajax_ and wp_ajax_nopriv_ hooks, as the base controller's getPer...
- CVSS:
- 5.3
- Affected:
- up to 1.4.12
- Fixed in:
- 1.5.4
- Disclosed:
- Jul 10, 2026
CVE-2026-6803 on NVD →
AI Copilot – Content Generator <= 1.5.4 - Unauthenticated SQL Injection
high
The AI Copilot – Content Generator plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append addition...
- CVSS:
- 7.5
- Affected:
- up to 1.5.4
- Fixed in:
- 1.5.5
- Disclosed:
- Jul 9, 2026
CVE-2026-59515 on NVD →
AI Chatbot & Workflow Automation by AIWU <= 1.5.3 - Unauthenticated Privilege Escalation
critical
The AI Copilot – Content Generator plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.5.3. This makes it possible for unauthenticated attackers to elevate privileges to that of an administrator.
- CVSS:
- 9.8
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.4
- Disclosed:
- Jun 26, 2026
CVE-2026-9810 on NVD →
AI Chatbot & Workflow Automation by AIWU <= 1.4.17 - Unauthenticated Privilege Escalation
critical
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.17. This makes it possible for unauthenticated attackers to elevate their privileges.
- CVSS:
- 9.8
- Affected:
- up to 1.4.17
- Fixed in:
- 1.4.19
- Disclosed:
- Jun 1, 2026
CVE-2026-48879 on NVD →
AI Chatbot & Workflow Automation by AIWU <= 1.4.14 - Unauthenticated Stored Cross-Site Scripting via 'X-Forwarded-For' Header
medium
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' header in versions up to, and including, 1.4.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary we...
- CVSS:
- 6.4
- Affected:
- up to 1.4.14
- Fixed in:
- 1.4.15
- Disclosed:
- May 19, 2026
CVE-2026-2955 on NVD →
AI Chatbot & Workflow Automation by AIWU <= 1.5.6 - Unauthenticated SQL Injection in getListForTbl()
high
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.6 due to insufficient escaping on user supplied parameters and lack of sufficient preparation on the existing SQL query in the getListForTbl() function. This makes it possible for unaut...
- CVSS:
- 7.5
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.8
- Disclosed:
- May 11, 2026
CVE-2026-2993 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database