Impact
A missing authorization flaw allows attackers to bypass the access control that protects the AI Content Writing Assistant plugin. The vulnerability permits the use of the plugin’s content generation and image creation functionality without proper authentication, giving an adversary the ability to generate content or potentially expose underlying data. The weakness is classified as Missing Authorization (CWE‑862).
Affected Systems
The issue affects the WordPress AI Content Writing Assistant (Content Writer, ChatGPT, Image Generator) All in One plugin for all accounts that install versions n/a through 1.1.7. Users running any of these releases on their WordPress sites are potentially exposed.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. EPSS is below 1%, implying a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be via the plugin’s web interface, where an unauthenticated or low‑privileged user can target HTTP endpoints to trigger the unauthorized actions.
OpenCVE Enrichment