Impact
The vulnerability allows an attacker to insert sensitive information into messages that are sent through the plugin’s AI ChatBot. This leads to potential exposure of confidential data stored or processed by the plugin. The weakness is categorized as CWE-201, indicating sensitive data exposure in software with insufficient masking or removal of such data before transmission.
Affected Systems
The impacted product is the Ays Pro AI ChatBot with ChatGPT and Content Generator plugin for WordPress, versions up to and including 2.6.6. Any installation of this plugin in a WordPress site that is running those versions is susceptible.
Risk and Exploitability
The CVSS score of 7.5 places the vulnerability in the high severity range, and the EPSS score of 3% shows that there is a modest probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker could exploit this weakness by interacting with the chatbot to trigger the generation of responses that include embedded sensitive data; the exact attack vector is inferred to be through normal plugin usage.
OpenCVE Enrichment