Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability exists in the AI Copilot – Content Generator plugin for WordPress, allowing unauthenticated attackers to bypass authorization controls. This could enable attackers to create new administrator accounts and gain full control of affected websites. The main concern is confirming relevance and exposure for sites using this plugin.
- Unauthorized users can take over websites.
- Critical plugin flaw permits admin account creation.
- Confirm plugin relevance and exposure.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker could exploit this vulnerability by crafting a request to a WordPress site that uses the AI Copilot – Content Generator plugin. The attacker would leverage the plugin's exposure of a nonce value in public JavaScript to bypass authorization checks. This allows them to create a malicious workflow that executes a user creation action, ultimately granting them administrator privileges and full control over the website.
- Accessible via public pages.
- Triggered by creating a new admin user.
- Leads to full site takeover.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow unauthenticated attackers to create a new administrator-level user account on a WordPress site. This is possible when the AI Copilot plugin is configured to render its shortcode or public chatbot on a frontend page, exposing necessary data that bypasses authorization checks.
- Website administrator access is at risk.
- Unauthenticated users can create new accounts.
- Full site takeover is a realistic consequence.
Operational Fix
Recommended remediation, mitigation, and detection steps
The WordPress AI Copilot – Content Generator plugin's authorization bypass vulnerability, allowing unauthenticated attackers to create administrator accounts, likely falls under the purview of website owners and their associated platform or infrastructure teams. The initial practical step involves identifying all WordPress sites utilizing this plugin, determining if their public-facing shortcodes or chatbots render the vulnerable JavaScript, and then confirming the business criticality of affected sites before proceeding with a remediation plan.
- WordPress site owners and platform teams own remediation.
- Verify plugin usage and frontend shortcode/chatbot exposure.
- Plan coordinated updates or disable the plugin.