Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104741— AI Puffer <= 2.4.89 - Missing Authorization to Authenticated (Subscriber+) Global Plugin Settings Modification via ajax_save_cpt_indexing_options AJAX Endpoint

Quick assessment

Affected
senols AI Puffer – AI Chatbot, AI Writer & Automation
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 插件“The AI Puffer – Chat. Create. Automate.”(原名 AI Power)在 2.4.89 及所有早期版本中存在授权绕过漏洞。该漏洞是由于插件未正确验证用户是否被授权执行特定操作所致。这使得具备订阅者(Subscriber)或更高权限的经过身份验证的攻击者,能够修改全局插件索引和向量搜索配置选项(具体为 和 ),包括分块(chunking)参数、文件上传可见性以及每个自定义文章类型(CPT)字段索引设置等。这些更改会影响所有使用该插件的用户。 此漏洞仅在特定

CVSS 3.1 · Low EPSS 0.27% · P18

Possible ATT&CK Techniques 1 AI

T1136.001 · Local Account

Affected Version Matrix 1

VendorProduct Version RangeStatus
senols AI Puffer – AI Chatbot, AI Writer & Automation ≤ 2.4.89 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104741

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
AI Puffer <= 2.4.89 - Missing Authorization to Authenticated (Subscriber+) Global Plugin Settings Modification via ajax_save_cpt_indexing_options AJAX Endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify global plugin indexing and vector-search configuration options (aipkit_training_general_settings and aipkit_indexing_field_settings), including chunking parameters, file upload visibility, and per-CPT field indexing settings, affecting all users of the plugin. This is only exploitable in configurations where an administrator has granted 'sources' module access to a lower-privileged role via the plugin's Role Manager.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
senols AI Puffer – AI Chatbot, AI Writer & Automation 0 ~ 2.4.89 -

II. Public POCs for CVE-2026-104741

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104741

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-104741 (4)

Vendor Advisories for CVE-2026-104741 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104741

No comments yet


Leave a comment