Authorization Bypass Vulnerability in AI Puffer Plugin for WordPress
CVE-2026-104741
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-104741?
The AI Puffer β Chat. Create. Automate. plugin for WordPress has a vulnerability that allows authenticated attackers to bypass authorization controls. This issue affects all versions up to and including 2.4.89, resulting from the plugin's inability to properly validate user permissions when performing certain actions. Attackers with subscriber-level access or higher can manipulate critical global settings, such as indexing and vector-search configurations. This exploitation requires that an administrator has previously granted access to the 'sources' module for lower-privileged roles through the plugin's Role Manager, making it essential for site administrators to review and restrict permissions to mitigate potential risks.
Affected Version(s)
AI Puffer β AI Chatbot, AI Writer & Automation 0 <= 2.4.89