/Vulnerability Library

AI ChatBot with ChatGPT by AYS <= 2.6.6 - Unauthenticated API Key Exposure

CVE-2025-62039
Verified

Description

AYS AI ChatBot with ChatGPT and Content Generator <= 2.6.6 contains an insertion of sensitive information into sent data vulnerability caused by improper handling of embedded sensitive data, letting attackers retrieve sensitive information, exploit requires crafted input.

Severity

High

Published Date

April 22, 2026

Template Author

pussycat0x

CVE-2025-62039.yaml
7.5Severity

CVSS Metrics

References

https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ays-chatgpt-assistant/ai-chatbot-with-chatgpt-and-content-generator-by-ays-266-unauthenticated-information-exposure

Remediation Steps

Update to the latest version beyond 2.6.6.