CVE-2026-104742
Received Received - Intake

Authorization Bypass in AI Puffer WordPress Plugin

Vulnerability report for CVE-2026-104742, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify global site-wide semantic search settings, including vector provider, embedding provider, embedding model, target ID, number of results, and no-results text stored in aipkit_options, that are otherwise restricted to administrators. Exploitation requires that an administrator has previously granted the Knowledge Base ('sources') module to the attacker's role via the Role Manager, as this access is not available to lower-privileged users by default.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
senols AI Puffer – AI Chatbot, AI Writer & Automation 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The AI Puffer WordPress plugin up to version 2.4.89 has an authorization bypass flaw. Authenticated users with subscriber-level access or higher can modify global semantic search settings, including vector and embedding providers, due to improper permission checks. This requires prior access to the Knowledge Base module via the Role Manager.

Detection Guidance

Check WordPress sites running the AI Puffer plugin versions up to 2.4.89. Look for unauthorized modifications to aipkit_options in the database, particularly changes to semantic search settings by non-admin users. Review user role permissions for the Knowledge Base module access.

Impact Analysis

An attacker could change site-wide search settings, potentially altering how content is indexed or displayed. This may disrupt normal site functionality or expose sensitive information if embedding models are misconfigured. The impact is limited to settings changes, not direct data theft or full admin access.

Compliance Impact

This vulnerability allows authenticated attackers with subscriber-level access to modify global site-wide semantic search settings, which could potentially expose or alter sensitive data. This may impact compliance with GDPR or HIPAA if such modifications lead to unauthorized data access or disclosure, though the specific impact depends on the site's configuration and data handling practices.

Mitigation Strategies
  • Update the AI Puffer plugin to the latest version beyond 2.4.89 immediately.
  • Audit and restrict user roles to remove unauthorized access to the Knowledge Base module.
  • Review aipkit_options in the database for suspicious changes and revert if found.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104742. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart