Junglewise Threat Intelligence

CVE-2026-13009: wupsales AI Copilot , Content Generator SQL injection in order parameter

CVE-2026-13009 · Severity: medium · CVSS 6.5 · Published 2026-07-23

Executive brief

The AI Copilot – Content Generator plugin for WordPress, which helps automate content creation, contains a security flaw that could allow logged-in users to access sensitive information from the website's database. By exploiting this vulnerability, an attacker with even low-level access (such as a subscriber) could potentially steal user data or other confidential site information. This could lead to data breaches and unauthorized access to internal site records.

Technical details

The AI Copilot – Content Generator plugin for WordPress is vulnerable to a generic SQL injection due to insufficient escaping and lack of preparation on SQL queries within the 'order[0][dir]' parameter. The vulnerability exists in the AJAX handler and can be reached by authenticated attackers with subscriber-level access or higher. While the handler requires a valid 'waic-nonce', this nonce is emitted on the front-end when specific shortcodes ([waic_form] or [aiwu-form]) are rendered, which can be triggered by contributor-level users. Successful exploitation allows an attacker to append additional SQL queries to existing ones, enabling the extraction of sensitive data from the WordPress database.

Affected products

  • wupsales AI Copilot – Content Generator up to and including 1.5.4

Timeline

  • 2026-07-23: advisory: NVD publication date
  • 2026-07-23: disclosed: Wordfence advisory published

References