Description
The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'ays_chatgpt_save_wp_media' function in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to upload media files.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 03 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ays-pro
Ays-pro ai Chatbot With Chatgpt Wordpress Wordpress wordpress |
|
| Vendors & Products |
Ays-pro
Ays-pro ai Chatbot With Chatgpt Wordpress Wordpress wordpress |
Thu, 27 Nov 2025 09:45:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-12-03T21:09:06.610Z
Reserved: 2025-11-18T20:23:35.769Z
Link: CVE-2025-13381
Updated: 2025-12-03T21:09:03.307Z
Status : Awaiting Analysis
Published: 2025-11-27T10:15:51.220
Modified: 2025-12-01T15:39:33.110
Link: CVE-2025-13381
No data.
OpenCVE Enrichment
Updated: 2025-11-27T16:26:35Z
Weaknesses