A vulnerability classified as critical has been found in wupsales AI Copilot Plugin up to 1.5.6 on WordPress. Affected is the function
wp_create_user of the component Shortcode. The manipulation of the argument waic-nonce leads to authorization bypass.
This vulnerability is referenced as CVE-2026-14526. Remote exploitation of the attack is possible. No exploit is available.