Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-9810: AIWU Plugin < 1.5.4 - Unauthenticated Access to Administrator Privileges
CVE-2026-9810
CVE-2026-9810
Summary
The AIWU plugin for WordPress doesn't properly check user access, allowing attackers to gain administrator privileges without logging in. This can lead to sensitive tasks being performed without permission. Update the plugin to version 1.5.4 or later to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unknown | ai copilot | < 1.5.4 |
Original title
The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who ...
Original description
The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public OAuth flow to execute privileged MCP tools as an administrator, including arbitrary user creation and role escalation.
Vulnerability type
CWE-269
Improper Privilege Management
- https://wpscan.com/vulnerability/6378a370-fe2f-48e7-984f-6e6c575dba60/ exploit vdb-entry technical-description
Published: 17 Jul 2026 · Updated: 18 Jul 2026 · First seen: 17 Jul 2026