CVE · Medium

CVE-2023-51527 — AI Puffer – Chat. Create. Automate. (formerly AI Power) [gpt3-ai-content-generator] < 1.8.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-51527 AI Puffer – Chat. Create. Automate. (formerly AI Power) [gpt3-ai-content-generator] < 1.8.3 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 1.8.3 1.8.3 2023-12-27

CVE-2023-51527

The AI Puffer plugin for WordPress, versions up to 1.8.2, contains a vulnerability in the wpaicg_export_logs_callback() function that fails to verify user permissions before allowing log exports. An attacker without authentication can exploit this flaw to download plugin logs that may include confidential data, potentially exposing sensitive information to unauthorized parties.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.