Record summary

CVE-2024-7714 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0. Multiple actions are accessible: 'ays_chatgpt_disconnect', 'ays_chatgpt_connect', and 'ays_chatgpt_save_feedback'

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 27, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

AI ChatBot with ChatGPT and Content Generator by AYS

Default status: unaffected

CVE ListBefore 2.1.0affected

Default status: unknown

CVE ListBefore 2.1.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMAI Assistant with ChatGPT by AYS <= 2.0.9 - Unauthenticated AJAX CallsCVSS 6.5

The plugin lacks sufficient access controls allowing an unauthenticated user to disconnect the plugin from OpenAI, thereby disabling the plugin. Multiple actions are accessible: ays_chatgpt_disconnect, ays_chatgpt_connect, and ays_chatgpt_save_feedback

Impact

Unauthenticated attackers can disconnect the plugin from OpenAI and manipulate plugin settings through unprotected AJAX endpoints, causing denial of service and disrupting ChatGPT assistant functionality.

Remediation

Fixed in 2.1.0

WeaknessesCWE-284
Authorss4e-io
Template tagscvecve2024ays-chatgpt-assistantwordpresswp-pluginwpiacvulnai
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Source: ProjectDiscovery

References

2