Executive brief
A vulnerability exists in the AI Chatbot & Workflow Automation plugin for WordPress, which is used to automate content generation and customer interactions. Due to a security flaw, unauthorized individuals can delete data from the plugin's database tables without needing to log in. This could lead to the loss of chatbot configurations, workflow records, or other plugin-specific data, potentially disrupting automated business processes.
Technical details
The vulnerability is classified as Missing Authorization (CWE-862) within the plugin's AJAX handling logic. Specifically, the base controller's getPermissions() method returns an empty array, and critical methods such as 'removeGroup' and 'clear' are not included in getNoncedMethods(). Because these actions are registered under both wp_ajax_ and wp_ajax_nopriv_ hooks without proper capability checks or nonce verification, the authorization gate defaults to true. An unauthenticated remote attacker can exploit this by sending crafted AJAX requests to delete records by ID or truncate entire module tables.
Affected products
- wupsales AI Chatbot & Workflow Automation by AIWU (AI Copilot – Content Generator) up to, and including, 1.4.12
Timeline
- 2026-07-11: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/classes/controller.php
- https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/classes/controller.php
- https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/classes/controller.php
- https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/classes/frame.php
- https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/classes/model.php
- https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/trunk/classes/controller.php
- https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/trunk/classes/controller.php