Authorization Bypass in AI Puffer Plugin for WordPress
CVE-2026-104742

3.1LOW

What is CVE-2026-104742?

The AI Puffer – Chat. Create. Automate. plugin for WordPress is susceptible to an authorization bypass issue that allows authenticated users with subscriber-level access and above to alter critical site-wide settings. This vulnerability stems from inadequate verification of user permissions within the plugin, enabling unauthorized modifications to global semantic search settings. Specifically, attackers can adjust settings related to vector providers, embedding models, and result display texts, which are typically limited to administrators. For exploitation to be possible, an administrator must have inadvertently granted the Knowledge Base module access to the assailant's role via the plugin's Role Manager. This flaw can lead to substantial security risks if not addressed promptly.

Affected Version(s)

AI Puffer – AI Chatbot, AI Writer & Automation 0 <= 2.4.89

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.