CVE-2026-9810

The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public OAuth flow to execute privileged MCP tools as an administrator, including arbitrary user creation and role escalation.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-17 07:16

Updated : 2026-07-17 15:44


NVD link : CVE-2026-9810

Mitre link : CVE-2026-9810

CVE.ORG link : CVE-2026-9810


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management