CVE-2026-13009 | wupsales AI Copilot Plugin up to 1.5.4 on WordPress AJAX handler order[0][dir] sql injection
A vulnerability marked as critical has been reported in wupsales AI Copilot Plugin up to 1.5.4 on WordPress. Impacted is an unknown function of the component AJAX handler. This manipulation of the argument order[0][dir] causes sql injection.
The identification of this vulnerability is CVE-2026-13009. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More