CVE-2024-7714
AI Assistant with ChatGPT by AYS <= 2.0.9 - Unauthenticated AJAX Calls
Record summary
CVE-2024-7714 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0. Multiple actions are accessible: 'ays_chatgpt_disconnect', 'ays_chatgpt_connect', and 'ays_chatgpt_save_feedback'
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 27, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
AI ChatBot with ChatGPT and Content Generator by AYSDefault status: unaffected | CVE List | Before 2.1.0 | affected |
ai_chatbot_with_chatgptBrowse ays-pro / ai_chatbot_with_chatgptDefault status: unknown | CVE List | Before 2.1.0 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMAI Assistant with ChatGPT by AYS <= 2.0.9 - Unauthenticated AJAX CallsCVSS 6.5
The plugin lacks sufficient access controls allowing an unauthenticated user to disconnect the plugin from OpenAI, thereby disabling the plugin. Multiple actions are accessible: ays_chatgpt_disconnect, ays_chatgpt_connect, and ays_chatgpt_save_feedback
Impact
Unauthenticated attackers can disconnect the plugin from OpenAI and manipulate plugin settings through unprotected AJAX endpoints, causing denial of service and disrupting ChatGPT assistant functionality.
Remediation
Fixed in 2.1.0
Source: ProjectDiscovery