CVE Database /
CVE-2025-47470
CVE · Medium
CVE-2025-47470 — AI Puffer – Chat. Create. Automate. (formerly AI Power) [gpt3-ai-content-generator] < 1.9.15
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-47470
|
AI Puffer – Chat. Create. Automate. (formerly AI Power) [gpt3-ai-content-generator] < 1.9.15 |
Cross-Site Request Forgery (CSRF) |
Medium
4.3
|
< 1.9.15
|
1.9.15 |
2025-05-07 |
—
|
CVE-2025-47470
The GPT3 AI Content Writer plugin for WordPress contains a security flaw in versions up to 1.9.14, allowing malicious actors to exploit Cross-Site Request Forgery vulnerabilities by manipulating the wpaicg_generate_custom_prompt function's validation process. This weakness enables unauthenticated attackers to deceive site administrators into executing certain actions, such as clicking on links, thereby facilitating unauthorized prompt generation.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings