Unauthorized Data Access in Originality.ai AI Checker Plugin for WordPress
CVE-2025-10901

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 October 2025

What is CVE-2025-10901?

The Originality.ai AI Checker plugin for WordPress contains a security vulnerability that allows authenticated users with Subscriber-level access and above to gain unauthorized access to sensitive data within the wp_originalityai_log database table. The root cause of this issue is a missing capability check in the 'ai_get_table' function, which permits attackers to read information including post titles, scan scores, and credits used. This flaw affects all versions up to and including 1.0.12, posing serious risks to the confidentiality of the data processed by the plugin.

Affected Version(s)

Originality.ai AI Checker * <= 1.0.12

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonas Benjamin Friedli
.
CVE-2025-10901 : Unauthorized Data Access in Originality.ai AI Checker Plugin for WordPress