
PEACH
Un cadre d’isolation des locataires
CVE-2026-9810 is an unauthenticated privilege escalation vulnerability in the AI Copilot (AI Chatbot & Workflow Automation by AIWU) WordPress plugin affecting all versions before 1.5.4. The flaw allows unauthenticated attackers who complete the public OAuth flow to execute privileged MCP (Model Context Protocol) tools as an administrator, including arbitrary user creation and role escalation. It was publicly disclosed on June 26, 2026, and assigned a CVSS score of 9.8 (Critical) (WPScan, GitHub Advisory). The vulnerability was discovered and reported by researcher Khaled Alenazi (Nxploited) (WPScan).
The root cause is improper privilege management (CWE-269), classified under OWASP Top 10 A2: Broken Authentication and Session Management. The plugin fails to bind OAuth access tokens to a specific WordPress user account, instead accepting any valid OAuth token as proof of an administrator session. An attacker can initiate and complete the publicly accessible OAuth flow — without any prior authentication — and then present the resulting token to the plugin's MCP tool interface, which grants full administrator-level access. This design flaw effectively bypasses all authentication controls for privileged operations (WPScan, GitHub Advisory).
Successful exploitation grants an unauthenticated attacker full administrator privileges on the affected WordPress site. Attackers can create new administrator accounts, escalate existing user roles, and execute any privileged MCP tool available to the plugin. This results in complete compromise of site integrity and confidentiality, and may serve as a foothold for further attacks such as malware injection, data exfiltration, or lateral movement within hosted environments (WPScan, GitHub Advisory).
wp_usermeta or audit logs.wp_users, wp_usermeta) with administrator roles assigned to unfamiliar accounts.Update the AI Copilot WordPress plugin (ai-copilot-content-generator) to version 1.5.4 or later immediately, as this version contains the fix (WPScan, GitHub Advisory). If immediate patching is not possible, consider disabling or deactivating the plugin until the update can be applied. After patching, audit all WordPress user accounts for unauthorized administrator accounts or unexpected role escalations, and review MCP tool execution logs for suspicious activity.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."