CVE-2026-97305: WordPress AI Chatbot for WordPress – Hyve Lite plugin <= 2.0.2 - Insecure Direct Object References (IDOR) vulnerability
Published Oct 5, 2026
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in Themeisle AI Chatbot for WordPress – Hyve Lite hyve-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Chatbot for WordPress – Hyve Lite: from n/a through 2.0.2.
Affected Software
1 affected component
Themeisle AI Chatbot for WordPress – Hyve Lite<=2.0.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Themeisle AI Chatbot for WordPress – Hyve Liteto a version that resolves this vulnerability.Fixed in 2.0.3
Event History
Oct 5, 2026
CVE Published
via MITRE·06:08 PM
Data Sourced
via MITRE·06:08 PM
RemedyDescriptionWeakness