{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-14526/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-14526"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AI Copilot – Content Generator (\u003c= 1.5.6)"],"_cs_severities":["critical"],"_cs_tags":["web-application","wordpress","cve-2026-14526","auth-bypass"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe AI Copilot - Content Generator plugin for WordPress (versions 1.5.6 and earlier) contains a critical authorization bypass vulnerability. The plugin fails to adequately verify user permissions during the execution of workflow actions. Because the application exposes a required nonce in the \u003ccode\u003eWAIC_DATA.waicNonce\u003c/code\u003e JavaScript object on any page rendering the \u003ccode\u003e[aiwu-form]\u003c/code\u003e shortcode or public chatbot, the nonce check effectively fails as an authorization control. An unauthenticated attacker can capture this nonce and craft a request to the plugin's workflow engine, injecting a \u003ccode\u003ewp_create_user\u003c/code\u003e action node with \u003ccode\u003erole=administrator\u003c/code\u003e. This allows the creation of unauthorized administrative accounts, resulting in full site compromise. Defenders must monitor for unauthorized user creation events and identify the presence of this plugin on their WordPress instances.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker navigates to a public-facing WordPress page that utilizes the \u003ccode\u003e[aiwu-form]\u003c/code\u003e shortcode or the plugin's public chatbot interface.\u003c/li\u003e\n\u003cli\u003eAttacker inspects the source code of the page to locate the \u003ccode\u003eWAIC_DATA.waicNonce\u003c/code\u003e value within the rendered JavaScript.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious workflow request intended for the plugin's backend endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker inserts a \u003ccode\u003ewp_create_user\u003c/code\u003e action node into the workflow, configuring the payload to set the \u003ccode\u003erole\u003c/code\u003e parameter to \u003ccode\u003eadministrator\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker transmits the crafted request to the WordPress site, including the extracted \u003ccode\u003ewaic-nonce\u003c/code\u003e to bypass the authentication check.\u003c/li\u003e\n\u003cli\u003eThe plugin processes the workflow engine request, executing the \u003ccode\u003ewp_create_user\u003c/code\u003e function with the attacker-supplied parameters.\u003c/li\u003e\n\u003cli\u003eA new administrative user is created within the WordPress database.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates with the newly created account to establish persistent, full-access administrative control over the site.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full site takeover. An attacker can gain persistent administrative access, leading to the exfiltration of sensitive site data, modification of site content, redirection of users to malicious infrastructure, or use of the server as a node for further attacks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the \u0026quot;AI Copilot - Content Generator\u0026quot; plugin to a version later than 1.5.6 to patch the authorization bypass vulnerability (CVE-2026-14526).\u003c/li\u003e\n\u003cli\u003eIf the update cannot be applied, disable the plugin and remove any pages containing the \u003ccode\u003e[aiwu-form]\u003c/code\u003e shortcode or the public chatbot interface.\u003c/li\u003e\n\u003cli\u003eAudit the WordPress database for suspicious administrative accounts created by unknown sources, specifically monitoring user registration logs for entries generated via the plugin's backend logic.\u003c/li\u003e\n\u003cli\u003eReview web server logs for HTTP POST requests to plugin-specific workflow endpoints that contain \u003ccode\u003ewp_create_user\u003c/code\u003e payloads.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-08T07:37:50Z","date_published":"2026-08-08T07:37:50Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wp-plugin-auth-bypass/","summary":"An authorization bypass vulnerability in the AI Copilot - Content Generator WordPress plugin allows unauthenticated attackers to create administrator accounts and achieve full site takeover via malformed workflow execution.","title":"Authorization Bypass in AI Copilot - Content Generator WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-wp-plugin-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-14526","version":"https://jsonfeed.org/version/1.1"}