WordPress Plugin Vulnerabilities

AI Assistant with ChatGPT by AYS <= 2.0.9 - Unauthenticated AJAX Calls

Description

The plugin lacks sufficient access controls allowing an unauthenticated user to disconnect the plugin from OpenAI, thereby disabling the plugin. Multiple actions are accessible: 'ays_chatgpt_disconnect', 'ays_chatgpt_connect', and 'ays_chatgpt_save_feedback'

Proof of Concept

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Kieran Burge
Submitter
Kieran Burge
Submitter website
Verified
Yes

Timeline

Publicly Published
2024-09-05 (about 1 year ago)
Added
2024-09-05 (about 1 year ago)
Last Updated
2025-08-25 (about 4 months ago)

Other