CVE-2026-6804
MEDIUMAI Copilot – Content Generator < 1.4.12 - Authorization Bypass
Title source: ruleDescription
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to publish draft WordPress posts, exposing unpublished content, or unpublish live content, causing service disruption, by supplying arbitrary scenario IDs.
References (10)
Core 10
Scores
CVSS v3
5.3
EPSS
0.0035
EPSS Percentile
28.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (1)
wupsales/AI Copilot – Content Generator
< 1.4.12
Published
Jul 11, 2026
Tracked Since
Jul 11, 2026