Unauthorized Data Access in Originality.ai AI Checker Plugin for WordPress
CVE-2025-10901
4.3MEDIUM
What is CVE-2025-10901?
The Originality.ai AI Checker plugin for WordPress contains a security vulnerability that allows authenticated users with Subscriber-level access and above to gain unauthorized access to sensitive data within the wp_originalityai_log database table. The root cause of this issue is a missing capability check in the 'ai_get_table' function, which permits attackers to read information including post titles, scan scores, and credits used. This flaw affects all versions up to and including 1.0.12, posing serious risks to the confidentiality of the data processed by the plugin.
Affected Version(s)
Originality.ai AI Checker * <= 1.0.12