CVE-2024-7713: AI Chatbot with ChatGPT by AYS <= 2.0.9 - Unauthenticated OpenAI Key Disclosure
Published Sep 27, 2024
·Updated
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain it
Affected Software
1 affected component
ays-pro Chatgpt Assistant Wordpress<2.1.0
Event History
Sep 27, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-7713?
CVE-2024-7713 is considered a critical vulnerability due to the exposure of the Open AI API Key.
2
How do I fix CVE-2024-7713?
To fix CVE-2024-7713, update the AI ChatBot with ChatGPT and Content Generator plugin to version 2.1.0 or later.
3
Who is affected by CVE-2024-7713?
Users of the AI ChatBot with ChatGPT and Content Generator plugin by AYS versions prior to 2.1.0 are affected by CVE-2024-7713.
4
What does CVE-2024-7713 disclose?
CVE-2024-7713 discloses the Open AI API Key to unauthenticated users, posing a significant security risk.
5
Is there a workaround for CVE-2024-7713?
There are no known workarounds for CVE-2024-7713; upgrading to the patched version is the only solution.