PT-2026-7241 · Ays Pro · Ai Chatbot With Chatgpt/Content Generator

Nabil Irawan

·

Publicado

2026-02-10

·

Atualizado

2026-03-13

·

CVE-2026-1336

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions AYS ChatGPT plugin for WordPress versions up to and including 2.7.5
Description The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is susceptible to unauthorized access and modification of data. This is due to missing capability checks within the store data() and get chatgpt api key() functions. This allows unauthenticated attackers to view, modify, or delete the plugin’s ChatGPT API key. The issue was partially addressed in version 2.7.5 and fully resolved in version 2.7.6.
Recommendations Update to version 2.7.6 or later.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1336

Produtos afetados

Ai Chatbot With Chatgpt/Content Generator