Executive brief
The AIWU (AI Copilot Content Generator) plugin for WordPress contains a critical security flaw that allows unauthorized users to gain administrative control over a website. By exploiting this vulnerability, an attacker can elevate their permissions to the highest level, potentially leading to full site takeover, data theft, or the installation of malicious software. This issue affects all versions of the plugin up to 1.4.17, and site owners are urged to update to version 1.4.19 immediately.
Technical details
An Incorrect Privilege Assignment vulnerability (CWE-266) exists in the Sergey AIWU (AI Copilot Content Generator) plugin for WordPress. The flaw allows an unauthenticated remote attacker to escalate their privileges, potentially gaining administrative access to the WordPress environment. The vulnerability stems from improper permission checks within the plugin's logic. Attackers can exploit this over the network without any user interaction. The issue is resolved in version 1.4.19; versions 1.4.17 and below are confirmed to be vulnerable.
Affected products
- Sergey AIWU (AI Copilot Content Generator) <= 1.4.17
Timeline
- 2026-01-08: other: Reported by researcher daroo
- 2026-06-01: disclosed: Vulnerability published by Patchstack and NVD
- 2026-06-01: patched: Patch released in version 1.4.19