CVE-2026-13009: The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Param
Summary
The AI Copilot – Content Generator plugin for WordPress has a SQL injection vulnerability (a weakness that lets attackers insert malicious database commands) in versions up to 1.5.4 through the 'order[0][dir]' parameter. Authenticated attackers with subscriber-level access or higher can exploit this to extract sensitive information from the database because the plugin fails to properly filter user input before using it in database queries.
Vulnerability Details
6.5(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
network
low
low
none
July 23, 2026
Classification
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-13009
First tracked: July 23, 2026 at 08:08 AM
Classified by LLM (prompt v3) · confidence: 65%