Sceawere
Vulnerability Detail
CVE-2026-104742UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
AI Puffer Authorization Bypass Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.1
- Creation Date
- 2h ago
- Vendor
- senols
- Product
- AI Puffer – AI Chatbot, AI Writer & Automation
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify global site-wide semantic search settings, including vector provider, embedding provider, embedding model, target ID, number of results, and no-results text stored in aipkit_options, that are otherwise restricted to administrators. Exploitation requires that an administrator has previously granted the Knowledge Base ('sources') module to the attacker's role via the Role Manager, as this access is not available to lower-privileged users by default.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.1",
"pubDate": "2026-10-10T06:16:39.240Z",
"pubdate": "2026-10-10T06:16:39.240Z",
"executiveSummary": "The AI Puffer plugin for WordPress, versions up to and including 2.4.89, contains an authorization bypass vulnerability stemming from insufficient access control checks. This flaw enables authenticated users with subscriber-level permissions or higher to modify critical site-wide semantic search configurations, which are intended to be restricted exclusively to administrative users.\nThe vulnerability resides within the plugin's configuration management logic, specifically regarding the storage and update of 'aipkit_options'. While the flaw technically allows unauthorized settings modification, successful exploitation is contingent upon an administrator explicitly granting the user role access to the Knowledge Base ('sources') module via the Role Manager.\nThe risk implication is significant, as a compromised or malicious subscriber can manipulate search parameters, such as embedding providers and model settings, potentially leading to service degradation, unauthorized data exposure, or the injection of malicious search configurations. This vulnerability represents a failure in the principle of least privilege, as the plugin fails to enforce role-based access control (RBAC) at the function level during configuration updates.\nAffected systems include any WordPress installation running the AI Puffer plugin in the specified version range. Remediation requires an immediate audit of user roles and careful restriction of module access until a vendor-supplied patch is applied.",
"technicalDetails": "The root cause of this vulnerability is an improper implementation of authorization checks within the AI Puffer plugin's backend request handlers. The plugin fails to validate whether the user initiating a request to modify site-wide semantic search parameters possesses the requisite administrative capabilities. Instead, the application relies on weak authorization logic that does not explicitly verify the user's role against the sensitive action being performed.\nSpecifically, the 'aipkit_options' array, which dictates global search behavior, is vulnerable to unauthorized updates. Attackers can leverage this by crafting malicious HTTP requests that invoke the plugin's update functions. These functions are intended to be gated by administrative privileges but currently lack mandatory checks, such as 'current_user_can('manage_options')' or equivalent capability verification.\nThe exploitation flow is as follows: 1) An administrator modifies the WordPress Role Manager settings to grant a low-privileged role (e.g., subscriber) access to the 'sources' module. 2) An authenticated attacker assigned to this role identifies the API endpoint or AJAX action responsible for updating search settings. 3) The attacker intercepts or reconstructs the request, supplying arbitrary values for parameters such as 'vector_provider', 'embedding_provider', 'embedding_model', 'target_id', 'number_of_results', and 'no_results_text'. 4) The plugin processes the request without validating the user's identity against the administrative requirements for changing global settings. 5) The 'aipkit_options' are updated in the WordPress database, successfully overriding the intended configuration.\nThe technical impact includes the unauthorized alteration of core plugin functionality. By modifying the 'embedding_provider' or 'embedding_model', an attacker could disrupt the integrity of the semantic search results, potentially forcing the plugin to interact with malicious or unauthorized infrastructure. Furthermore, manipulating the 'no_results_text' could facilitate cross-site scripting (XSS) attacks if the plugin does not properly sanitize these inputs before rendering them on the front end. This vulnerability is restricted to environments where the administrator has modified the Role Manager configuration, but within those environments, it provides an escalation path for subscribers to control sensitive plugin-wide behavior that affects the entire application's search capabilities."
}