Impact
The AI Copilot – Content Generator plugin for WordPress contains an authorization bypass that lets an unauthenticated attacker create an administrator account and take complete control of the site. The flaw arises from the plugin failing to verify a user’s role when a malicious workflow containing a wp_create_user action is saved and executed. Exploiting this weakness results in full administrative privileges.
Affected Systems
WordPress installations running AI Copilot – Content Generator version 1.5.6 or earlier are affected. No other vendors or products are listed.
Risk and Exploitability
The vulnerability has a CVSS score of 9.8, indicating critical severity. It is usable by someone with no authentication on any site where the [aiwu-form] shortcode or the public chatbot renders, because the waic-nonce is exposed in public JavaScript and thus ineffective. No exploit probability is listed and the issue is not in CISA’s KEV catalog, but the high severity and wide exposure mean attackers can readily abuse it if the plugin remains unpatched.
OpenCVE Enrichment