Originality.ai AI Checker WordPress Plugin Missing Authorization Vulnerability in Data Access
Vulnerability
A vulnerability exists in the Originality.ai AI Checker plugin for WordPress, all versions through 1.0.12, due to a lack of proper capability checks in the 'ai_get_table' function. This flaw allows authenticated attackers with Subscriber-level access or higher to access and read all data from the wp_originalityai_log database table. The exposed data may include post titles, scan scores, credits used, and other related information.
Impact
Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive information logged by the Originality.ai AI Checker plugin, including originality scores and details about scanned posts.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
