CVE Database /
CVE-2023-51527
CVE · Medium
CVE-2023-51527 — AI Puffer – Chat. Create. Automate. (formerly AI Power) [gpt3-ai-content-generator] < 1.8.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-51527
|
AI Puffer – Chat. Create. Automate. (formerly AI Power) [gpt3-ai-content-generator] < 1.8.3 |
Exposure of Sensitive Information to an Unauthorized Actor |
Medium
5.3
|
< 1.8.3
|
1.8.3 |
2023-12-27 |
—
|
CVE-2023-51527
The AI Puffer plugin for WordPress, versions up to 1.8.2, contains a vulnerability in the wpaicg_export_logs_callback() function that fails to verify user permissions before allowing log exports. An attacker without authentication can exploit this flaw to download plugin logs that may include confidential data, potentially exposing sensitive information to unauthorized parties.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings