HomeCVE Intelligence › CVE-2026-9810
CVSS 9.1 CRITICAL Security Vulnerability

CVE-2026-9810: CVE-2026-9810 - AI Chatbot & Workflow Automation by AIWU < 1.5.4 - Unauthenticated Privil…

CVE ID : CVE-2026-9810 Published : July 17, 2026, 6 a.m. | 59minutes ago Description : The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as a…

9.1CVSS Score
CRITICALSeverity
NOCISA KEV
Security VulnerabilityImpact Type

📋 Vulnerability Details

CVE IDCVE-2026-9810
VendorUnknown Vendor
Affected ProductUnknown Product
Vulnerability TypeSecurity Vulnerability
CVSS Score9.1 (CRITICAL)
Actively Exploited❌ No known exploitation
Patch StatusPending Vendor Disclosure
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via sentinel_apex)

🔬 Technical Analysis

CVE ID : CVE-2026-9810

Published : July 17, 2026, 6 a.m. | 59minutes ago

Description : The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public OAuth flow to execute privileged MCP tools as an administrator, including arbitrary user creation and role escalation.

Severity: 0.0 | NA

Visit the link for more deta

🎯 Known Indicators of Compromise

{"type":"indicator","value":"CVE-2026-9810","confidence_score":23.5,"first_seen":"2026-07-17","source_count":1}
⚡ DETECTION RULES AVAILABLE

Get CVE-2026-9810 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence