CVE-2026-9810: The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any val
Summary
The AI Copilot WordPress plugin before version 1.5.4 has a security flaw where OAuth access tokens (temporary credentials that grant access to accounts) are not properly tied to specific WordPress users, allowing attackers who complete the public login process to gain administrator privileges and perform dangerous actions like creating new users or changing user permissions.
Solution / Mitigation
Update the AI Copilot WordPress plugin to version 1.5.4 or later.
Vulnerability Details
EPSS: 0.0%
July 17, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-9810
First tracked: July 17, 2026 at 08:08 AM
Classified by LLM (prompt v3) · confidence: 75%