The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0. Multiple actions are accessible: 'ays_chatgpt_disconnect', 'ays_chatgpt_connect', and 'ays_chatgpt_save_feedback'
History

Fri, 27 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Ays-pro
Ays-pro ai Chatbot With Chatgpt
CPEs cpe:2.3:a:ays-pro:ai_chatbot_with_chatgpt:*:*:*:*:*:*:*:*
Vendors & Products Ays-pro
Ays-pro ai Chatbot With Chatgpt
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Sep 2024 06:15:00 +0000

Type Values Removed Values Added
Description The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0. Multiple actions are accessible: 'ays_chatgpt_disconnect', 'ays_chatgpt_connect', and 'ays_chatgpt_save_feedback'
Title AI Assistant with ChatGPT by AYS <= 2.0.9 - Unauthenticated AJAX Calls
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-09-27T06:00:06.287Z

Updated: 2024-09-27T16:22:19.390Z

Reserved: 2024-08-12T18:35:24.099Z

Link: CVE-2024-7714

cve-icon Vulnrichment

Updated: 2024-09-27T15:15:12.636Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-27T06:15:12.750

Modified: 2024-09-30T12:46:20.237

Link: CVE-2024-7714

cve-icon Redhat

No data.