Impact
Sergey AIWU ai-copilot-content-generator for WordPress accepts user input without proper sanitization, enabling attackers to inject arbitrary SQL through blind injection. The flaw is a classic input validation weakness, classified as CWE-89, and may allow unauthorized reading of sensitive data or alteration of database contents, thereby compromising confidentiality and integrity of the application.
Affected Systems
All WordPress sites that have installed Sergey AIWU ai-copilot-content-generator version 1.5.4 or earlier are affected. The vendor is Sergey and the product is AIWU. No other WordPress core versions are specified as impacted.
Risk and Exploitability
The CVSS score of 9.3 classifies this issue as critical, but the EPSS score of less than 1% indicates a low current exploitation probability. It is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote actor sending specially crafted requests—such as via HTTP GET or POST—to unfiltered plugin endpoints, exploiting blind SQL injection to infer database schemas, exfiltrate data, or manipulate records without immediate detection.
OpenCVE Enrichment