CVE-2024-7714: AI Assistant with ChatGPT by AYS <= 2.0.9 - Unauthenticated AJAX Calls
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0. Multiple actions are accessible: 'ayschatgptdisconnect', 'ayschatgptconnect', and 'ayschatgptsavefeedback'
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7714?
CVE-2024-7714 is rated as a medium severity vulnerability due to the potential for unauthorized access.
How do I fix CVE-2024-7714?
To fix CVE-2024-7714, update the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin to version 2.1.0 or later.
Who is affected by CVE-2024-7714?
CVE-2024-7714 affects any user running versions of the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin prior to 2.1.0.
What does CVE-2024-7714 allow an attacker to do?
CVE-2024-7714 allows an unauthenticated user to disconnect the plugin from OpenAI, effectively disabling its functionality.
Is there a workaround for CVE-2024-7714?
There are no effective workarounds for CVE-2024-7714 other than upgrading the plugin to the latest version.