Sceawere

Vulnerability Detail

CVE-2026-104741UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

AI Puffer Authorization Bypass Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3.1
Creation Date
2h ago
Vendor
senols
Product
AI Puffer – AI Chatbot, AI Writer & Automation
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify global plugin indexing and vector-search configuration options (aipkit_training_general_settings and aipkit_indexing_field_settings), including chunking parameters, file upload visibility, and per-CPT field indexing settings, affecting all users of the plugin. This is only exploitable in configurations where an administrator has granted 'sources' module access to a lower-privileged role via the plugin's Role Manager.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.1",
  "pubDate": "2026-10-10T06:16:39.087Z",
  "pubdate": "2026-10-10T06:16:39.087Z",
  "executiveSummary": "The AI Puffer plugin for WordPress (formerly AI Power) is susceptible to an authorization bypass vulnerability affecting versions 2.4.89 and earlier.\nThe vulnerability stems from improper access control validation within the plugin's configuration management functions, allowing authenticated users with subscriber-level permissions to modify critical settings.\nSpecifically, an attacker can manipulate global indexing configurations, including vector-search parameters and CPT (Custom Post Type) field indexing, by intercepting and modifying administrative requests.\nThis vulnerability is exploitable provided that an administrator has enabled 'sources' module access for lower-privileged roles via the plugin's internal Role Manager.\nSuccessful exploitation allows unauthorized configuration changes, which may lead to the degradation of search accuracy, leakage of sensitive indexing data, or the potential manipulation of AI output vectors.\nThe risk is categorized as significant for installations relying on granular role delegation for plugin management, as it grants attackers the capability to reconfigure core plugin behavior without requisite administrative privileges.",
  "technicalDetails": "The root cause of this vulnerability lies in the insufficient server-side verification of user capabilities within the plugin's request handling logic for configuration updates. The affected components, identified as 'aipkit_training_general_settings' and 'aipkit_indexing_field_settings', fail to perform a strict capability check (e.g., using current_user_can()) before processing POST requests destined for configuration modification.\nAlthough the plugin implements a Role Manager, the authorization logic relies on flawed permission verification rather than rigorous enforcement of WordPress access control lists. Consequently, if a low-privileged user is granted access to the 'sources' module, the application fails to restrict that user's interaction with global configuration endpoints.\nThe attack flow begins when an authenticated subscriber or higher-privileged user initiates a request to the plugin’s configuration save action. Because the underlying controller does not validate whether the session user possesses the 'manage_options' capability or equivalent administrative rights, the server accepts and executes the update command.\nThe attacker can transmit a crafted payload to the plugin’s API endpoints containing modified parameters for 'aipkit_training_general_settings'. This allows the attacker to manipulate chunking parameters, change file upload visibility settings, and alter per-CPT field indexing configurations. By modifying these fields, an attacker can influence how the AI engine indexes content, potentially excluding sensitive data from search or injecting malicious configurations into the indexing pipeline.\nThe exploit requires the victim's environment to have enabled access to the 'sources' module for non-admin roles. In such configurations, the attack surface is exposed to any authenticated user within the compromised role. Once the configuration is altered, the impact is global, affecting all users of the plugin by forcing the system to utilize the attacker's defined (and potentially insecure or malicious) search and indexing parameters.\nThis vulnerability does not involve memory corruption or remote code execution directly but represents a logic flaw in authorization design that undermines the integrity of the plugin's core training and indexing functions. Because the configuration is stored in the WordPress database, the persistence of these unauthorized changes remains until they are manually reverted by a legitimate administrator."
}
CVE-2026-104741: AI Puffer Authorization Bypass Vulnerability (LOW Severity, CVSS: 3.1) | Sceawere