Impact
The AI Copilot plugin fails to bind OAuth access tokens to a WordPress user and accepts any valid token as an administrator session. This improper authorization weakness (CWE-269) allows attackers who complete the public OAuth flow to execute privileged MCP tools with administrator privileges, enabling arbitrary user creation and role escalation.
Affected Systems
Installations of the AI Copilot WordPress plugin older than version 1.5.4 are affected. The plugin is distributed through WordPress and can be configured to allow OAuth authentication, making any unauthenticated visitor capable of exploiting the flaw.
Risk and Exploitability
Based on the description, it is inferred that the attackers only need to perform the normal OAuth authorization step; once a token is issued, the plugin grants full administrative rights without further validation. The CVSS score of 9.8 indicates critical severity, while the EPSS score of < 1 % suggests a low probability of immediate exploitation. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment