Executive brief
The AI Copilot – Content Generator plugin for WordPress, which helps automate content creation, contains a security flaw that could allow logged-in users to access sensitive information from the website's database. By exploiting this vulnerability, an attacker with even low-level access (such as a subscriber) could potentially steal user data or other confidential site information. This could lead to data breaches and unauthorized access to internal site records.
Technical details
The AI Copilot – Content Generator plugin for WordPress is vulnerable to a generic SQL injection due to insufficient escaping and lack of preparation on SQL queries within the 'order[0][dir]' parameter. The vulnerability exists in the AJAX handler and can be reached by authenticated attackers with subscriber-level access or higher. While the handler requires a valid 'waic-nonce', this nonce is emitted on the front-end when specific shortcodes ([waic_form] or [aiwu-form]) are rendered, which can be triggered by contributor-level users. Successful exploitation allows an attacker to append additional SQL queries to existing ones, enabling the extraction of sensitive data from the WordPress database.
Affected products
- wupsales AI Copilot – Content Generator up to and including 1.5.4
Timeline
- 2026-07-23: advisory: NVD publication date
- 2026-07-23: disclosed: Wordfence advisory published
References
- https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.5.4/classes/model.php
- https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.5.4/classes/table.php
- https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.5.4/modules/workspace/controller.php
- https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.5.4/modules/workspace/models/tasks.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3612849%40ai-copilot-content-generator&new=3612849%40ai-copilot-content-generator
- https://www.wordfence.com/threat-intel/vulnerabilities/id/2a965a23-5594-4925-8104-6f387a60ab49?source=cve