PT-2026-7241 · Ays Pro · Ai Chatbot With Chatgpt/Content Generator
Nabil Irawan
·
Publicado
2026-02-10
·
Atualizado
2026-03-13
·
CVE-2026-1336
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
AYS ChatGPT plugin for WordPress versions up to and including 2.7.5
Description
The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is susceptible to unauthorized access and modification of data. This is due to missing capability checks within the
store data() and get chatgpt api key() functions. This allows unauthenticated attackers to view, modify, or delete the plugin’s ChatGPT API key. The issue was partially addressed in version 2.7.5 and fully resolved in version 2.7.6.Recommendations
Update to version 2.7.6 or later.
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ai Chatbot With Chatgpt/Content Generator