Feed/CVE-2026-9810
CVE-2026-9810CRITICALCVSS 9.8

CVE-2026-9810

Published Jul 17, 2026·Updated Jul 17, 2026

NVD Description

The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public OAuth flow to execute privileged MCP tools as an administrator, including arbitrary user creation and role escalation.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free