PT-2025-48253 · WordPress+1 · Wordpress+1

Chokri Hammedi

·

Published

2025-11-27

·

Updated

2025-11-27

·

CVE-2025-13378

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress versions prior to 2.7.1
Description The software is susceptible to a Server-Side Request Forgery (SSRF) issue. This allows unauthenticated attackers to make web requests to arbitrary locations originating from the web application. Exploitation can lead to querying and modifying information from internal services through the ays chatgpt pinecone upsert function.
Recommendations Update to version 2.7.1 or later.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13378

Affected Products

Ai Chatbot With Chatgpt/Content Generator
Wordpress