Extension WordPress

Vulnérabilités AI Copilot – Content Generator

Cette page rassemble les failles publiées pour AI Copilot – Content Generator, leurs plages de versions affectées et les correctifs signalés dans la base locale.

6Vulnérabilités
1Critiques
5Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de AI Copilot – Content Generator

6 fiches

CVE-2026-6804 Moyenne · 5,3
AI Copilot – Content Generator

AI Chatbot & Workflow Automation by AIWU <= 1.4.12 – Missing Authorization to Unauthenticated Arbitrary Modification via 'publishTasks' and 'unpublishTasks' AJAX Actions

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This is due to the plugin not properly verifying that a user is authorized…

Versions affectées

*-1.4.12

Correctif

1.5.4

Publication

10/07/2026

CVE-2026-6803 Moyenne · 5,3
AI Copilot – Content Generator

AI Chatbot & Workflow Automation by AIWU <= 1.4.12 – Missing Authorization to Unauthenticated Arbitrary Data Deletion via AJAX Actions 'removeGroup' and 'clear'

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12. This is due to missing capability checks and nonce verification on AJAX actions registered…

Versions affectées

*-1.4.12

Correctif

1.5.4

Publication

10/07/2026

CVE-2026-2955 Moyenne · 6,4
AI Copilot – Content Generator

AI Chatbot & Workflow Automation by AIWU <= 1.4.14 – Unauthenticated Stored Cross-Site Scripting via 'X-Forwarded-For' Header

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' header in versions up to, and including, 1.4.14 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-1.4.14

Correctif

1.4.15

Publication

19/05/2026

CVE-2026-2993 Élevée · 7,5
AI Copilot – Content Generator

AI Chatbot & Workflow Automation by AIWU <= 1.4.17 – Unauthenticated SQL Injection in getListForTbl()

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.17 due to insufficient escaping on user supplied parameters and lack of sufficient preparation on the…

Versions affectées

*-1.4.17

Correctif

Non indiqué

Publication

11/05/2026

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités