WordPress 插件“The AI Puffer – Chat. Create. Automate.”(原名 AI Power)在 2.4.89 及所有早期版本中存在授权绕过漏洞。该漏洞是由于插件未正确验证用户是否被授权执行特定操作所致。这使得具备订阅者(Subscriber)或更高权限的经过身份验证的攻击者,能够修改全局插件索引和向量搜索配置选项(具体为 和 ),包括分块(chunking)参数、文件上传可见性以及每个自定义文章类型(CPT)字段索引设置等。这些更改会影响所有使用该插件的用户。 此漏洞仅在特定
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| senols | AI Puffer – AI Chatbot, AI Writer & Automation | ≤ 2.4.89 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| senols | AI Puffer – AI Chatbot, AI Writer & Automation | 0 ~ 2.4.89 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet