Skip to content

Known CVE

AI Assistant with ChatGPT by AYS <= 2.0.9 - Unauthenticated AJAX Calls

The plugin lacks sufficient access controls allowing an unauthenticated user to disconnect the plugin from OpenAI, thereby disabling the plugin. Multiple actions are accessible: ays_chatgpt_disconnect, ays_chatgpt_connect, and ays_chatgpt_save_feedback

CVE-2024-7714

Medium2024CVSS 6.5CWE-284

cve2024 · ays-chatgpt-assistant · wordpress · wp-plugin · wp · iac · vuln · ai

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website