Description
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to publish draft WordPress posts, exposing unpublished content, or unpublish live content, causing service disruption, by supplying arbitrary scenario IDs.
Published: 2026-07-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an authorization bypass that allows unauthenticated users to modify content through the publishTasks and unpublishTasks AJAX actions. By supplying arbitrary scenario IDs, an attacker can publish draft posts that were intended to remain hidden or unpublish posts that are already live. This can lead to exposure of sensitive content and disruption of the site’s normal publishing workflow. The weakness is a missing authorization check and is identified as CWE-862.

Affected Systems

The issue affects the Wupsales AI Copilot – Content Generator WordPress plugin, in all versions up to and including 1.4.12. The vulnerability is present in every installation of that plugin before the fix is applied. No other plugins or WordPress core components are implicated.

Risk and Exploitability

The CVSS score is 5.3, indicating a medium severity. The EPSS score of less than 1% shows a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw can be triggered as AJAX endpoints, an attacker could exploit this remotely from any network that can reach the WordPress site. The consequence for the site owner is potential data leakage and disruption of content availability.

Generated by OpenCVE AI on July 29, 2026 at 09:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the AI Copilot – Content Generator plugin to the latest version (>=1.4.13) or later to remove the missing authorization checks.
  • If an immediate update is not possible, block the publishTasks and unpublishTasks AJAX endpoints with a web‑application firewall, .htaccess rule, or by disabling them through server configuration.
  • Monitor the WordPress dashboard for any unauthorized content modifications or unexpected changes in published status to detect potential exploitation.

Generated by OpenCVE AI on July 29, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wupsales
Wupsales ai Copilot – Content Generator
Vendors & Products Wordpress
Wordpress wordpress
Wupsales
Wupsales ai Copilot – Content Generator

Sat, 11 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Description The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to publish draft WordPress posts, exposing unpublished content, or unpublish live content, causing service disruption, by supplying arbitrary scenario IDs.
Title AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Modification via 'publishTasks' and 'unpublishTasks' AJAX Actions
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Wupsales Ai Copilot – Content Generator
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-14T14:25:22.248Z

Reserved: 2026-04-21T14:59:43.137Z

Link: CVE-2026-6804

cve-icon Vulnrichment

Updated: 2026-07-14T14:25:18.124Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T09:30:18Z

Weaknesses