Junglewise Threat Intelligence

CVE-2026-59515: Sergey AIWU ai-copilot-content-generator SQL injection

CVE-2026-59515 · Severity: critical · CVSS 9.3 · Published 2026-07-13

Executive brief

The AIWU ai-copilot-content-generator plugin for WordPress is vulnerable to a critical security flaw that allows attackers to interact directly with the website's database. By exploiting this vulnerability, an unauthorized user could potentially steal sensitive information or disrupt site operations. This type of flaw is frequently targeted in automated mass-exploit campaigns against WordPress websites.

Technical details

A Blind SQL Injection vulnerability exists in the Sergey AIWU ai-copilot-content-generator plugin for WordPress due to improper neutralization of special elements used in an SQL command. The flaw allows an unauthenticated remote attacker to send specially crafted requests to the application, leading to unauthorized database queries. Successful exploitation could result in the exfiltration of sensitive data from the WordPress database. The vulnerability affects all versions up to and including 1.5.4 and is resolved in version 1.5.5.

Affected products

  • Sergey AIWU AIWU ai-copilot-content-generator <= 1.5.4

Timeline

  • 2026-06-27: disclosed: Reported by VanTastic to Patchstack
  • 2026-07-09: advisory: Patchstack advisory published
  • 2026-07-13: advisory: NVD published CVE-2026-59515
  • 2026-07-09: patched: Version 1.5.5 released to address the vulnerability

References

Related threats