AI Copilot – Content Generator

AI Copilot – Content Generator has 11 disclosed vulnerabilities in the WordSec catalog, all reported in 2026; 9 are fixed and 2 remain unpatched as of August 2026. Their average CVSS score is 7.7, and the most serious one scores 9.8 out of 10. Severity breakdown: 4 critical and 3 high. 2026 was the busiest year with 11 disclosures.

The most common weakness is Missing Authorization, behind 3 of the records (27%). Other recurring categories include SQL Injection, Improper Privilege Management.

9 of the records (82%) have a vendor fix, while 2 remain unpatched. The oldest unresolved one dates back to 2026.

7 independent researchers contributed these findings, most of them (5) reported by Kazuma Matsumoto.

01234567891011.05.2026Today11.05.20267.5AI Chatbot & Workflow Automation by AIWU <= 1.4.17 - Unauthenticated SQL Injection in getListForTbl() CVSS 7.5 · 11.05.202619.05.20266.4AI Chatbot & Workflow Automation by AIWU <= 1.4.14 - Unauthenticated Stored Cross-Site Scripting via 'X-Forwarded-For' Header CVSS 6.4 · 19.05.202601.06.20269.8AI Chatbot & Workflow Automation by AIWU <= 1.4.17 - Unauthenticated Privilege Escalation CVSS 9.8 · 01.06.202626.06.20269.8AI Chatbot & Workflow Automation by AIWU <= 1.5.3 - Unauthenticated Privilege Escalation CVSS 9.8 · 26.06.202609.07.20267.5AI Copilot – Content Generator <= 1.5.4 - Unauthenticated SQL Injection CVSS 7.5 · 09.07.202610.07.20265.3AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via AJAX Actions 'removeGroup' and 'clear' CVSS 5.3 · 10.07.20265.3AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Modification via 'publishTasks' and 'unpublishTasks' AJAX Actions CVSS 5.3 · 10.07.202622.07.20266.5AI Copilot <= 1.5.4 - Authenticated (Subscriber+) SQL Injection via 'order[0][dir]' Parameter CVSS 6.5 · 22.07.202628.07.20269.8AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation CVSS 9.8 · 28.07.202604.08.20267.5AI Chatbot & Workflow Automation by AIWU <= 1.4.6 - Missing Authorization to Unauthenticated Sensitive Information Exposure CVSS 7.5 · 04.08.202607.08.20269.8AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow Route CVSS 9.8 · 07.08.2026

Strategic Overview

Avg CVSSHigh
7.7/ 10
Patch Coverage82%
Open

2

Fixed

9

Get automatic notifications for all AI Copilot – Content Generator vulnerabilities before they are exploited.

Most severe open issueCVSS 9.8CVE-2026-14526

AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow Route

Read the full analysis

Vulnerability Records

11 records
2026-08-07 18:30CVE-2026-14526
9.8
Critical
d.v4n_s3cNo
2026-08-04 17:34CVE-2026-6639
7.5
High
Kazuma MatsumotoYes
2026-07-28 00:00CVE-2026-65507
9.8
Critical
qdtadYes
2026-07-22 20:39CVE-2026-13009
6.5
Medium
Wordfence PRISMYes
2026-07-10 15:18CVE-2026-6804
5.3
Medium
Kazuma MatsumotoYes
2026-07-10 15:17CVE-2026-6803
5.3
Medium
Kazuma MatsumotoYes
2026-07-09 00:00CVE-2026-59515
7.5
High
VanTasticYes
2026-06-26 00:00CVE-2026-9810
9.8
Critical
Khaled Alenazi (Nxploited)Yes
2026-06-01 00:00CVE-2026-48879
9.8
Critical
darooYes
2026-05-19 17:23CVE-2026-2955
6.4
Medium
Kazuma MatsumotoYes
Showing 1–10 of 11 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C