Description
The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'ays_chatgpt_save_wp_media' function in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to upload media files.
Published: 2025-11-27
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted Media File Upload
Action: Immediate Patch
AI Analysis

Impact

The AYS AI ChatBot plugin for WordPress fails to perform an authorization check in the ays_chatgpt_save_wp_media function for all releases up to and including 2.7.0. This flaw allows an unauthenticated user to upload media files, which can be used to deliver malicious payloads or exfiltrate sensitive data, thereby potentially compromising the web host or enabling further attacks. It represents a classic missing authorization weakness (CWE‑862).

Affected Systems

The vulnerability impacts the AYS AI ChatBot with ChatGPT and Content Generator plugin for WordPress, affecting all releases through and including version 2.7.0. Any WordPress site that has the plugin installed and has not updated beyond 2.7.0 is vulnerable, as the plugin’s media upload endpoint can be triggered without authentication.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity, with no authentication required and a potential for integrity compromise. The EPSS score is reported as less than 1%, suggesting a low exploitation probability at the current time. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by sending a crafted file upload request to the plugin’s endpoint from the public web interface, potentially delivering a malicious file that could result in remote code execution or other post‑exploitation activities.

Generated by OpenCVE AI on April 21, 2026 at 01:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the AYS AI ChatBot plugin to version 2.7.1 or later to restore the missing capability check.
  • If an upgrade cannot be performed immediately, temporarily disable the plugin or block the ays_chatgpt_save_wp_media endpoint to prevent unauthenticated uploads.
  • Restrict WordPress file upload settings to allow only approved MIME types and enforce reasonable file size limits, and ensure that user roles possess only the necessary capabilities for media handling.

Generated by OpenCVE AI on April 21, 2026 at 01:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Ays-pro
Ays-pro ai Chatbot With Chatgpt
Wordpress
Wordpress wordpress
Vendors & Products Ays-pro
Ays-pro ai Chatbot With Chatgpt
Wordpress
Wordpress wordpress

Thu, 27 Nov 2025 09:45:00 +0000

Type Values Removed Values Added
Description The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'ays_chatgpt_save_wp_media' function in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to upload media files.
Title AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 - Missing Authorization to Unauthenticated Media File Uploads
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Ays-pro Ai Chatbot With Chatgpt
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:19:08.617Z

Reserved: 2025-11-18T20:23:35.769Z

Link: CVE-2025-13381

cve-icon Vulnrichment

Updated: 2025-12-03T21:09:03.307Z

cve-icon NVD

Status : Deferred

Published: 2025-11-27T10:15:51.220

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-13381

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T01:15:20Z

Weaknesses