CVE-2026-39801: WordPress AIWU plugin <= 1.5.9 - Privilege Escalation vulnerability
Published Oct 10, 2026
·Updated
Subscriber Privilege Escalation in AIWU <= 1.5.9 versions.
Affected Software
1 affected component
WordPress AIWU plugin<=1.5.9
Event History
Oct 10, 2026
CVE Published
via MITRE·07:34 PM
Data Sourced
via MITRE·07:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an authenticated WordPress account or user interaction?
No. The CVSS vector indicates no privileges are required and no user interaction is needed.
2
Can this issue be exploited remotely?
Yes. The vulnerability is rated with network attack vector and low attack complexity, indicating remote exploitation is possible.
3
What is the potential security impact if exploitation succeeds?
The vulnerability can lead to privilege escalation, with high potential impact to confidentiality, integrity, and availability.