Impact
The Originality.ai AI Checker WordPress plugin has a missing capability check on the ai_get_table function, allowing any authenticated user with a Subscriber role or higher to access the wp_originalityai_log table. This table can contain post titles, scan scores, credits used, and other sensitive data, leading to an unauthorized disclosure of information. The underlying weakness is a missing authorization check (CWE-862).
Affected Systems
WordPress installations running the Originality.ai AI Checker plugin up to version 1.0.16 are vulnerable. The affected product is "Originality.ai AI Checker" provided by Originality.ai. No later versions are listed as affected.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk, while the EPSS score of less than 1% suggests a low likelihood of exploitation yet it is a potential vector for attackers with legitimate access. The vulnerability is not listed in CISA KEV. Exploitation requires only an authenticated account with Subscriber privileges, so the attacker can obtain the sensitive log data without needing to compromise the system externally.
OpenCVE Enrichment