Impact
The vulnerability is a missing authorization flaw (CWE‑862) in the Ays Pro AI ChatBot with ChatGPT and Content Generator WordPress plugin. This flaw allows an attacker to bypass normal access controls and perform actions that should be restricted to authorized users. As a result, an unauthenticated or low‑privilege user could potentially read, modify, or delete chatbot configuration and content, disrupting site functionality or exposing sensitive data.
Affected Systems
The affected product is the Ays Pro AI ChatBot with ChatGPT and Content Generator WordPress plugin, versions up to and including 2.7.4. Earlier versions are unknown; the vendor does not specify a lower bound.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate level of risk. The EPSS score of less than 1% suggests that exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. The apparent attack vector is likely via the plugin’s administrative interface; any user who can reach that interface can exploit the lack of authorization checks to gain unauthorized privileges. Because the issue stems from incorrectly configured access control, the attacker does not need to bypass authentication, making exploitation easier in a poorly secured environment.
OpenCVE Enrichment