Impact
The AI Puffer plugin for WordPress lacks proper verification that an authenticated user is authorized to modify semantic search settings via the ajax_save_semantic_search_settings action, allowing subscribers and higher roles to change site‑wide configuration such as vector provider, embedding model, and result count. This weakness is a violation of the authority control (CWE‑862) and can alter how content is generated or displayed, potentially harming the user experience and compromising site integrity.
Affected Systems
The vulnerability affects the AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin from senols, in all versions up to and including 2.4.89. WordPress sites running this plugin and having any subscriber‑level role that has been granted the Knowledge Base module capability are susceptible, as the role manager configuration can give non‑admin users the ability to change these settings.
Risk and Exploitability
The CVSS score of 3.1 indicates a low severity impact; EPSS data is not available and the issue is not listed in CISA KEV. The exploit requires an attacker to first obtain an account that has the Knowledge Base module enabled via the Role Manager, but no code execution or network‑wide compromise is possible. Consequently, the risk is confined to configuration tampering within the affected WordPress instance.
OpenCVE Enrichment