PT-2024-38529 · Ays · Ayswp Chatbot

Kieran Burge

·

Published

2024-09-26

·

Updated

2024-10-04

·

CVE-2024-7713

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin versions prior to 2.1.0
Description The issue allows unauthenticated users to obtain the Open AI API Key. This is due to the disclosure of the Open AI API Key in the plugin.
Recommendations For versions prior to 2.1.0, update to version 2.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's configuration to minimize the risk of exploitation.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-7713

Affected Products

Ayswp Chatbot