Impact
An access‑control flaw in the OpenAI Chatbot for WordPress – Helper plugin allows an unauthenticated attacker to invoke a delete routine that removes any content stored on the WordPress site. The issue is a CWE‑862 authorization bypass, enabling widespread data loss and denial of available content regardless of user role. The vulnerability undermines both integrity and availability of site data.
Affected Systems
The flaw affects WordPress installations that have installed Merkulove’s OpenAI Chatbot for WordPress – Helper plugin version 1.1.4 or earlier. Any site that has linked content managed through the plugin’s functionality is at risk, irrespective of the underlying WordPress core version.
Risk and Exploitability
The CVSS score of 7.5 categor as high severity, while an EPSS score of <1% indicates a relatively low probability of exploitation under current conditions. The issue is not listed in CISA’s KEV catalog. Attackers can trigger the vulnerable endpoint with a simple web request, requiring no authentication or additional credentials. Once triggered, any content can be deleted, posing a severe threat to sites with exposed plugin interfaces.
OpenCVE Enrichment