CVE · Medium

CVE-2025-47470 — AI Puffer – Chat. Create. Automate. (formerly AI Power) [gpt3-ai-content-generator] < 1.9.15

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-47470 AI Puffer – Chat. Create. Automate. (formerly AI Power) [gpt3-ai-content-generator] < 1.9.15 Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.9.15 1.9.15 2025-05-07

CVE-2025-47470

The GPT3 AI Content Writer plugin for WordPress contains a security flaw in versions up to 1.9.14, allowing malicious actors to exploit Cross-Site Request Forgery vulnerabilities by manipulating the wpaicg_generate_custom_prompt function's validation process. This weakness enables unauthenticated attackers to deceive site administrators into executing certain actions, such as clicking on links, thereby facilitating unauthorized prompt generation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.