{
  "title": "CVE del giorno — CVE-2026-9810 (CVSS 9,8, critica)",
  "title_variants": [
    {
      "id": "v0",
      "title": "CVE del giorno — CVE-2026-9810 (CVSS 9,8, critica)"
    },
    {
      "id": "v1",
      "title": "CVE-2026-9810: vulnerabilità critica, CVSS 9,8/10, tipo gestione privilegi impropria,"
    }
  ],
  "description": "CVE-2026-9810: vulnerabilità critica, CVSS 9,8/10, tipo gestione privilegi impropria, sfruttabile da remoto, senza privilegi, senza interazione utente. The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator…",
  "keywords": [
    "cve",
    "cve-2026-9810",
    "vulnerabilità",
    "vulnerabilità critica",
    "cwe-269",
    "cvss",
    "sicurezza informatica",
    "cybersecurity",
    "nvd",
    "aggiornamento di sicurezza"
  ],
  "scenes": [
    {
      "title": "CVE-2026-9810",
      "subtitle": "CVSS 9,8",
      "text": "CVE-2026-9810: gravità critica, punteggio CVSS 9,8 su 10 secondo il National Vulnerability Database."
    },
    {
      "title": "Gestione privilegi impropria",
      "subtitle": "gestione privilegi impropria · CVSS v3.1",
      "text": "The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public…"
    },
    {
      "title": "ESPOSIZIONE E MITIGAZIONE",
      "subtitle": "sfruttabile da remoto, senza privilegi, senza interazione utente",
      "text": "Vulnerabilità sfruttabile da remoto, senza privilegi, senza interazione utente. Applica tempestivamente l'aggiornamento del fornitore e consulta l'avviso ufficiale su NVD."
    }
  ],
  "publication_date": "2026-07-20T00:28:16.839Z",
  "duration": 20,
  "topic": "cve",
  "lang": "it",
  "translation_group": "cve-2026-07-19",
  "poster": "cve-2026-07-19.jpg",
  "preview": "cve-2026-07-19.gif",
  "og_card": "cve-2026-07-19.og.jpg",
  "audiogram": "cve-2026-07-19.audiogram.mp4",
  "captions": "cve-2026-07-19.vtt",
  "generation": {
    "procedural": true,
    "ai_generated": [
      "background",
      "voice"
    ],
    "real_data_source": "official public API",
    "filmed_real_event": false,
    "disclosure": "Procedurally generated from real public-source data; abstract AI-generated backgrounds; synthetic (TTS) voice. No real event is filmed or altered."
  },
  "transcript_text": "CVE-2026-9810: gravità critica, punteggio CVSS 9,8 su 10 secondo il National Vulnerability Database. The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public… Vulnerabilità sfruttabile da remoto, senza privilegi, senza interazione utente. Applica tempestivamente l'aggiornamento del fornitore e consulta l'avviso ufficiale su NVD.",
  "transcript": [
    {
      "start": 0,
      "end": 6.667,
      "text": "CVE-2026-9810: gravità critica, punteggio CVSS 9,8 su 10 secondo il National Vulnerability Database."
    },
    {
      "start": 6.667,
      "end": 13.333,
      "text": "The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public…"
    },
    {
      "start": 13.333,
      "end": 20,
      "text": "Vulnerabilità sfruttabile da remoto, senza privilegi, senza interazione utente. Applica tempestivamente l'aggiornamento del fornitore e consulta l'avviso ufficiale su NVD."
    }
  ]
}