CVE-2025-13378: AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 - Unauthenticated Server-Side Request Forgery via 'pinecone_url' Parameter
The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.0 via the ayschatgptpineconeupsert function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13378?
CVE-2025-13378 has been classified as a critical severity vulnerability.
How do I fix CVE-2025-13378?
To fix CVE-2025-13378, upgrade the AYS AI ChatBot with ChatGPT and Content Generator plugin to version 2.8.0 or later.
Who is affected by CVE-2025-13378?
CVE-2025-13378 affects all versions of the AYS AI ChatBot with ChatGPT and Content Generator plugin up to and including version 2.7.0.
What type of vulnerability is CVE-2025-13378?
CVE-2025-13378 is a Server-Side Request Forgery (SSRF) vulnerability.
Can CVE-2025-13378 be exploited by unauthenticated attackers?
Yes, CVE-2025-13378 allows unauthenticated attackers to make web requests.