CVE-2026-9810
WordPress Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-9810 is an unauthenticated privilege escalation vulnerability in the AI Copilot (AI Chatbot & Workflow Automation by AIWU) WordPress plugin affecting all versions before 1.5.4. The flaw allows unauthenticated attackers who complete the public OAuth flow to execute privileged MCP (Model Context Protocol) tools as an administrator, including arbitrary user creation and role escalation. It was publicly disclosed on June 26, 2026, and assigned a CVSS score of 9.8 (Critical) (WPScan, GitHub Advisory). The vulnerability was discovered and reported by researcher Khaled Alenazi (Nxploited) (WPScan).

Détails techniques

The root cause is improper privilege management (CWE-269), classified under OWASP Top 10 A2: Broken Authentication and Session Management. The plugin fails to bind OAuth access tokens to a specific WordPress user account, instead accepting any valid OAuth token as proof of an administrator session. An attacker can initiate and complete the publicly accessible OAuth flow — without any prior authentication — and then present the resulting token to the plugin's MCP tool interface, which grants full administrator-level access. This design flaw effectively bypasses all authentication controls for privileged operations (WPScan, GitHub Advisory).

Impact

Successful exploitation grants an unauthenticated attacker full administrator privileges on the affected WordPress site. Attackers can create new administrator accounts, escalate existing user roles, and execute any privileged MCP tool available to the plugin. This results in complete compromise of site integrity and confidentiality, and may serve as a foothold for further attacks such as malware injection, data exfiltration, or lateral movement within hosted environments (WPScan, GitHub Advisory).

Étapes d’exploitation

  1. Reconnaissance: Identify WordPress sites running the AI Copilot (ai-copilot-content-generator) plugin version below 1.5.4 using tools like WPScan, Shodan, or manual inspection of plugin directories.
  2. Initiate OAuth flow: Access the plugin's publicly available OAuth authorization endpoint without any prior authentication credentials.
  3. Complete OAuth flow: Follow the standard OAuth authorization steps as a public/anonymous user, obtaining a valid OAuth access token from the provider.
  4. Present token as administrator: Submit the obtained OAuth token to the plugin's MCP tool interface or API endpoint. Due to the missing token-to-user binding, the plugin accepts this token as a valid administrator session.
  5. Execute privileged MCP tools: With administrator-level access, invoke privileged MCP tools to create new administrator accounts, escalate existing user roles, or perform other administrative actions on the WordPress site (WPScan).

Indicateurs de compromis

  • Logs: WordPress authentication logs showing new administrator account creation without a corresponding legitimate login event; unexpected role changes in wp_usermeta or audit logs.
  • File System: New or modified WordPress user records in the database (wp_users, wp_usermeta) with administrator roles assigned to unfamiliar accounts.
  • Network: Unusual OAuth flow completions originating from unknown or automated IP addresses, particularly followed immediately by MCP tool API calls; repeated OAuth token requests from a single IP.
  • Process/Application: MCP tool execution logs showing privileged operations (user creation, role escalation) triggered without a corresponding authenticated WordPress session from a known user (WPScan).

Atténuation et solutions de contournement

Update the AI Copilot WordPress plugin (ai-copilot-content-generator) to version 1.5.4 or later immediately, as this version contains the fix (WPScan, GitHub Advisory). If immediate patching is not possible, consider disabling or deactivating the plugin until the update can be applied. After patching, audit all WordPress user accounts for unauthorized administrator accounts or unexpected role escalations, and review MCP tool execution logs for suspicious activity.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté WordPress Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-13147CRITICAL9.1
  • kirki
NonOuiJul 20, 2026
CVE-2026-9833HIGH7.1
  • tag-groups
NonOuiJul 20, 2026
CVE-2026-13432MEDIUM5.4
  • image-sizes
NonOuiJul 20, 2026
CVE-2026-13156MEDIUM5.4
  • mailersend-official-smtp-integration
NonOuiJul 20, 2026
CVE-2026-8825MEDIUM4.9
  • elementor
NonOuiJul 20, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités