Description
The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'ays_chatgpt_save_wp_media' function in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to upload media files.
Problem types
Product status
* (semver)
Timeline
| 2025-11-18: | Vendor Notified |
| 2025-11-26: | Disclosed |
Credits
Chokri Hammedi
References
www.wordfence.com/...-0e34-4b0b-a04c-98ac94396989?source=cve
plugins.trac.wordpress.org/...ss-chatgpt-assistant-admin.php
plugins.trac.wordpress.org/...es/class-chatgpt-assistant.php
plugins.trac.wordpress.org/...ss-chatgpt-assistant-admin.php
plugins.trac.wordpress.org/...ss-chatgpt-assistant-admin.php
plugins.trac.wordpress.org/...ss-chatgpt-assistant-admin.php