The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0. Multiple actions are accessible: 'ays_chatgpt_disconnect', 'ays_chatgpt_connect', and 'ays_chatgpt_save_feedback'
History

Mon, 07 Oct 2024 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Ays-pro chatgpt Assistant
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:ays-pro:chatgpt_assistant:*:*:*:*:free:wordpress:*:*
Vendors & Products Ays-pro chatgpt Assistant

Fri, 27 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Ays-pro
Ays-pro ai Chatbot With Chatgpt
CPEs cpe:2.3:a:ays-pro:ai_chatbot_with_chatgpt:*:*:*:*:*:*:*:*
Vendors & Products Ays-pro
Ays-pro ai Chatbot With Chatgpt
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Sep 2024 06:15:00 +0000

Type Values Removed Values Added
Description The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0. Multiple actions are accessible: 'ays_chatgpt_disconnect', 'ays_chatgpt_connect', and 'ays_chatgpt_save_feedback'
Title AI Assistant with ChatGPT by AYS <= 2.0.9 - Unauthenticated AJAX Calls
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-09-27T06:00:06.287Z

Updated: 2024-09-27T16:22:19.390Z

Reserved: 2024-08-12T18:35:24.099Z

Link: CVE-2024-7714

cve-icon Vulnrichment

Updated: 2024-09-27T15:15:12.636Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-27T06:15:12.750

Modified: 2024-10-07T14:21:23.573

Link: CVE-2024-7714

cve-icon Redhat

No data.