Authorization Bypass in AI Puffer Plugin for WordPress
CVE-2026-104742
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-104742?
The AI Puffer β Chat. Create. Automate. plugin for WordPress is susceptible to an authorization bypass issue that allows authenticated users with subscriber-level access and above to alter critical site-wide settings. This vulnerability stems from inadequate verification of user permissions within the plugin, enabling unauthorized modifications to global semantic search settings. Specifically, attackers can adjust settings related to vector providers, embedding models, and result display texts, which are typically limited to administrators. For exploitation to be possible, an administrator must have inadvertently granted the Knowledge Base module access to the assailant's role via the plugin's Role Manager. This flaw can lead to substantial security risks if not addressed promptly.
Affected Version(s)
AI Puffer β AI Chatbot, AI Writer & Automation 0 <= 2.4.89