Extension WordPress
Vulnérabilités AI Copilot – Content Generator
Cette page rassemble les failles publiées pour AI Copilot – Content Generator, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de AI Copilot – Content Generator
6 fiches
AI Chatbot & Workflow Automation by AIWU <= 1.4.12 – Missing Authorization to Unauthenticated Arbitrary Modification via 'publishTasks' and 'unpublishTasks' AJAX Actions
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This is due to the plugin not properly verifying that a user is authorized…
*-1.4.12
1.5.4
10/07/2026
AI Chatbot & Workflow Automation by AIWU <= 1.4.12 – Missing Authorization to Unauthenticated Arbitrary Data Deletion via AJAX Actions 'removeGroup' and 'clear'
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12. This is due to missing capability checks and nonce verification on AJAX actions registered…
*-1.4.12
1.5.4
10/07/2026
AI Copilot – Content Generator <= 1.5.4 – Unauthenticated SQL Injection
The AI Copilot – Content Generator plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
*-1.5.4
1.5.5
09/07/2026
AI Chatbot & Workflow Automation by AIWU <= 1.4.17 – Unauthenticated Privilege Escalation
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.17. This makes it possible for unauthenticated attackers to elevate their privileges.
*-1.4.17
1.4.19
01/06/2026
AI Chatbot & Workflow Automation by AIWU <= 1.4.14 – Unauthenticated Stored Cross-Site Scripting via 'X-Forwarded-For' Header
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' header in versions up to, and including, 1.4.14 due to insufficient input sanitization and output escaping. This makes…
*-1.4.14
1.4.15
19/05/2026
AI Chatbot & Workflow Automation by AIWU <= 1.4.17 – Unauthenticated SQL Injection in getListForTbl()
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.17 due to insufficient escaping on user supplied parameters and lack of sufficient preparation on the…
*-1.4.17
Non indiqué
11/05/2026
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.