CVE-2026-25338: WordPress AI ChatBot with ChatGPT and Content Generator by AYS plugin <= 2.7.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in Ays Pro AI ChatBot with ChatGPT and Content Generator by AYS ays-chatgpt-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI ChatBot with ChatGPT and Content Generator by AYS: from n/a through <= 2.7.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25338?
CVE-2026-25338 is classified as a critical vulnerability due to its potential impact on unauthorized access to sensitive features.
How do I fix CVE-2026-25338?
To remediate CVE-2026-25338, update the AYS AI ChatBot with ChatGPT and Content Generator plugin to version 2.7.5 or later.
What causes CVE-2026-25338?
CVE-2026-25338 is caused by broken access control due to missing authorization checks in the plugin.
Who is affected by CVE-2026-25338?
CVE-2026-25338 affects users of the AYS AI ChatBot with ChatGPT and Content Generator plugin version 2.7.4 or lower on WordPress.
What actions should I take if vulnerable to CVE-2026-25338?
If you are vulnerable to CVE-2026-25338, immediately update the plugin and review user permissions to minimize risk.