Authorization Bypass Vulnerability in AI Puffer Plugin for WordPress
CVE-2026-104741

3.1LOW

What is CVE-2026-104741?

The AI Puffer – Chat. Create. Automate. plugin for WordPress has a vulnerability that allows authenticated attackers to bypass authorization controls. This issue affects all versions up to and including 2.4.89, resulting from the plugin's inability to properly validate user permissions when performing certain actions. Attackers with subscriber-level access or higher can manipulate critical global settings, such as indexing and vector-search configurations. This exploitation requires that an administrator has previously granted access to the 'sources' module for lower-privileged roles through the plugin's Role Manager, making it essential for site administrators to review and restrict permissions to mitigate potential risks.

Affected Version(s)

AI Puffer – AI Chatbot, AI Writer & Automation 0 <= 2.4.89

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.