Description
Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions.
Published: 2026-07-02
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An access‑control flaw in the OpenAI Chatbot for WordPress – Helper plugin allows an unauthenticated attacker to invoke a delete routine that removes any content stored on the WordPress site. The issue is a CWE‑862 authorization bypass, enabling widespread data loss and denial of available content regardless of user role. The vulnerability undermines both integrity and availability of site data.

Affected Systems

The flaw affects WordPress installations that have installed Merkulove’s OpenAI Chatbot for WordPress – Helper plugin version 1.1.4 or earlier. Any site that has linked content managed through the plugin’s functionality is at risk, irrespective of the underlying WordPress core version.

Risk and Exploitability

The CVSS score of 7.5 categor as high severity, while an EPSS score of <1% indicates a relatively low probability of exploitation under current conditions. The issue is not listed in CISA’s KEV catalog. Attackers can trigger the vulnerable endpoint with a simple web request, requiring no authentication or additional credentials. Once triggered, any content can be deleted, posing a severe threat to sites with exposed plugin interfaces.

Generated by OpenCVE AI on July 21, 2026 at 12:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or uninstall the affected plugin to remove the deletion endpoint entirely any content‑deletion code, ensuring only users with appropriate capabilities can perform deletes (addressing CWE‑862).
  • Check Merkulove’s website or contact the vendor to obtain an official update that patches this flaw; apply any released patch immediately when it becomes available.
  • Maintain regular full‑site backups and verify restoration procedures so deleted content can be recovered quickly if an attacker succeeds.
  • Monitor application logs for unexpected deletion activity and configure alerts for any removal of posts, pages,

Generated by OpenCVE AI on July 21, 2026 at 12:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Merkulove
Merkulove openai Chatbot For Wordpress – Helper
Wordpress
Wordpress wordpress
Vendors & Products Merkulove
Merkulove openai Chatbot For Wordpress – Helper
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions.
Title WordPress OpenAI Chatbot for WordPress – Helper plugin <= 1.1.4 - Arbitrary Content Deletion vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Merkulove Openai Chatbot For Wordpress – Helper
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T12:13:33.033Z

Reserved: 2025-12-29T11:19:41.703Z

Link: CVE-2025-69134

cve-icon Vulnrichment

Updated: 2026-07-02T12:13:29.460Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:15:02Z

Weaknesses