PT-2025-43589 · WordPress · Originality.Ai Ai Checker

Published

2025-10-24

·

Updated

2025-10-24

·

CVE-2025-10901

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Originality.ai AI Checker plugin for WordPress versions up to and including 1.0.12
Description The Originality.ai AI Checker plugin for WordPress is susceptible to unauthorized data access. This is due to a missing capability check within the ai get table() function. Authenticated attackers with Subscriber-level access or higher can read all data from the wp originalityai log database table. This data includes post titles, scan scores, and credits used.
Recommendations Update the Originality.ai AI Checker plugin for WordPress to a version beyond 1.0.12.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-10901

Affected Products

Originality.Ai Ai Checker