WordPress 插件 The AI Puffer – Chat. Create. Automate.(前身为 AI Power)在所有 2.4.89 及以下版本中存在授权绕过漏洞。该漏洞源于插件未正确验证用户是否有权执行特定操作。因此,具备订阅者(subscriber)及以上权限的经过身份验证的攻击者,可以修改全局站点范围的语义搜索设置,包括向量提供者(vector provider)、嵌入提供者(embedding provider)、嵌入模型(embedding model)、目标 ID(target ID
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| senols | AI Puffer – AI Chatbot, AI Writer & Automation | ≤ 2.4.89 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| senols | AI Puffer – AI Chatbot, AI Writer & Automation | 0 ~ 2.4.89 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet