PT-2026-7241 · Ays Pro · Ai Chatbot With Chatgpt/Content Generator

Nabil Irawan

·

Published

2026-02-10

·

Updated

2026-03-13

·

CVE-2026-1336

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions AYS ChatGPT plugin for WordPress versions up to and including 2.7.5
Description The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is susceptible to unauthorized access and modification of data. This is due to missing capability checks within the store data() and get chatgpt api key() functions. This allows unauthenticated attackers to view, modify, or delete the plugin’s ChatGPT API key. The issue was partially addressed in version 2.7.5 and fully resolved in version 2.7.6.
Recommendations Update to version 2.7.6 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1336

Affected Products

Ai Chatbot With Chatgpt/Content Generator