Junglewise Threat Intelligence

CVE-2026-9810: AIWU AI Copilot privilege escalation via OAuth token validation bypass

CVE-2026-9810 · Severity: info · CVSS 9.8 · Published 2026-07-17

Executive brief

The AI Copilot plugin for WordPress, which provides chatbot and workflow automation features, contains a critical security flaw in how it handles user logins. An attacker can bypass normal security checks by completing a public login process, which the plugin then incorrectly treats as a full administrator session. This allows an unauthorized person to take complete control of the website, create new admin accounts, and access sensitive data.

Technical details

The AI Copilot (ai-copilot-content-generator) plugin for WordPress fails to validate the binding between OAuth access tokens and specific WordPress user accounts. Because the plugin accepts any valid OAuth token as a legitimate administrator session, unauthenticated remote attackers can complete a public OAuth flow to impersonate an administrator. This vulnerability resides in the Model Context Protocol (MCP) implementation. Successful exploitation allows for unauthenticated privilege escalation, enabling the attacker to execute privileged tools, create arbitrary administrative users, and achieve full site compromise. The issue is resolved in version 1.5.4.

Affected products

  • AIWU AI Copilot (ai-copilot-content-generator) < 1.5.4

Timeline

  • 2026-06-26: disclosed
  • 2026-07-17: advisory: NVD publication date
  • 2026-07-17: patched: Fixed in version 1.5.4

References