PT-2026-7241 · Ays Pro · Ai Chatbot With Chatgpt/Content Generator
Nabil Irawan
·
Published
2026-02-10
·
Updated
2026-03-13
·
CVE-2026-1336
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
AYS ChatGPT plugin for WordPress versions up to and including 2.7.5
Description
The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is susceptible to unauthorized access and modification of data. This is due to missing capability checks within the
store data() and get chatgpt api key() functions. This allows unauthenticated attackers to view, modify, or delete the plugin’s ChatGPT API key. The issue was partially addressed in version 2.7.5 and fully resolved in version 2.7.6.Recommendations
Update to version 2.7.6 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ai Chatbot With Chatgpt/Content Generator