Impact
The AYS AI ChatBot plugin for WordPress fails to perform an authorization check in the ays_chatgpt_save_wp_media function for all releases up to and including 2.7.0. This flaw allows an unauthenticated user to upload media files, which can be used to deliver malicious payloads or exfiltrate sensitive data, thereby potentially compromising the web host or enabling further attacks. It represents a classic missing authorization weakness (CWE‑862).
Affected Systems
The vulnerability impacts the AYS AI ChatBot with ChatGPT and Content Generator plugin for WordPress, affecting all releases through and including version 2.7.0. Any WordPress site that has the plugin installed and has not updated beyond 2.7.0 is vulnerable, as the plugin’s media upload endpoint can be triggered without authentication.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, with no authentication required and a potential for integrity compromise. The EPSS score is reported as less than 1%, suggesting a low exploitation probability at the current time. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by sending a crafted file upload request to the plugin’s endpoint from the public web interface, potentially delivering a malicious file that could result in remote code execution or other post‑exploitation activities.
OpenCVE Enrichment