{"data":{"id":"d68f86ff-4e04-43bd-a0c5-4167df89dea3","title":"CVE-2026-9810: The AI Copilot  WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any val","summary":"The AI Copilot WordPress plugin before version 1.5.4 has a security flaw where OAuth access tokens (temporary credentials that grant access to accounts) are not properly tied to specific WordPress users, allowing attackers who complete the public login process to gain administrator privileges and perform dangerous actions like creating new users or changing user permissions.","solution":"Update the AI Copilot WordPress plugin to version 1.5.4 or later.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-9810","publishedAt":"2026-07-17T07:16:38.230Z","cveId":"CVE-2026-9810","cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["jailbreak"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["AI Copilot WordPress plugin"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-07-17T07:16:38.230Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":["AML.T0054"]}}