What is CVE-2026-13009?
This vulnerability allows SQL Injection via the 'order[0][dir]' parameter in the AI Copilot – Content Generator plugin for WordPress up to version 1.5.4. It can be exploited without admin access and may lead to data leakage. Users should immediately update the plugin to the latest version.
Azərbaycanca: Bu boşluq WordPress üçün AI Copilot – Content Generator plagininin 1.5.4-ə qədərki versiyalarında 'order[0][dir]' parametri vasitəsilə SQL Injection hücumuna imkan verir. İstismar admin panelə giriş tələb etmir və məlumat sızmasına səbəb ola bilər. İstifadəçilər plagini dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the WordPress AI Copilot – Content Generator plugin are affected by CVE-2026-13009?
This vulnerability affects the plugin up to version 1.5.4.
Does exploiting CVE-2026-13009 require admin access?
No, exploiting this vulnerability does not require admin access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.