CVE-2026-1336Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the store_data() and get_chatgpt_api_key() functions in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated attackers to view, modify or delete the plugin's ChatGPT API key. The vulnerability was partially fixed in version 2.7.5 and fully fixed in version 2.7.6

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-02); latest day: 1
  • 7 total mentions across 5 days

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-02-10: 1Mentions · 2026-03-02: 2Mentions · 2026-03-03: 2Mentions · 2026-03-11: 1Mentions · 2026-03-13: 1Technical Details · 2026-03-02: 2Technical Details · 2026-03-03: 102-1003-0203-0303-1103-13
Signal classification2 categories
Disclosure
685.7%
General
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-101
Disclosure1
2026-03-022
Disclosure2
2026-03-032
Disclosure2
2026-03-111
Disclosure1
2026-03-131
General1
Full discourse7 posts
  • Prateek Tomar@Prateektomar
    General

    Just published: Critical Analysis CVE-2026-1336 - The AI ChatBot with ChatGPT and Content.... Practical security guidance from the trenches. Read more: https://threatops.tech/blog/critical-analysis-cve-2026-1336-the-ai-chatbot-with-chatgpt-and-content-generator-by-ays-plu-march-

    Post summary

    The passage only refers to a blog post about CVE‑2026‑1336, lacking detailed technical analysis, PoC, or exploitation evidence.

    0001062
    95 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-1336 📊 Severity: 5.3 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-1336 #CVE-2026-1336 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/syhGCSALB2

    Post summary

    A new medium‑severity CVE affecting WordPress (CVE‑2026‑1336) has been announced, with basic severity details provided but no exploit or patch information.

    0001051
    64 followersView on X
  • Prateek Tomar@Prateektomar
    Disclosure

    Just published: Critical Analysis CVE-2026-1336 - The AI ChatBot with ChatGPT and Content.... Practical security guidance from the trenches. Read more: https://threatops.tech/blog/critical-analysis-cve-2026-1336-the-ai-chatbot-with-chatgpt-and-content-generator-by-ays-plu-march-

    Post summary

    The passage announces a new blog that provides a critical analysis of CVE‑2026‑1336, which appears to affect an AI chatbot built with ChatGPT.

    0000022
    92 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1336 Unauthenticated API Key Exposure in WordPress AYS ChatGPT Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1336

    Post summary

    The text announces CVE-2026-1336, noting an unauthenticated API key exposure in the WordPress AYS ChatGPT Plugin, but provides no further details or evidence of exploitation.

    0000055
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-1336 The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability ch… https://www.cve.org/CVERecord?id=CVE-2026-1336 ----- Traducción: CVE-2026-1336 El … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑1336, noting that the AYS WordPress plugin allows unauthorized access and data modification due to a missing capability, but it does not provide a PoC, exploit, or patch details.

    0000037
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1336 The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability ch… https://www.cve.org/CVERecord?id=CVE-2026-1336

    Post summary

    CVE-2026-1336 exposes the AYS WordPress plugin to unauthorized data access and modification because of missing capability checks.

    00000568
    56.6K followersView on X
  • Explain IT Again@xplain_it_again
    Disclosure

    Looks like the EU Commission's Ivanti EPMM MDM software had a bad case of CVE-2026-1281 and CVE-2026-1336 - not exactly a good look for the cybersecurity trailblazers. #cybersecurity #vulnerability #cyberattack https://explainitagain.wixsite.com/explain-it-again/post/european-commission-responds-to-mobile-device-cyberattack

    Post summary

    The EU Commission’s Ivanti EPMM MDM software is reported to have CVE‑2026‑1281 and CVE‑2026‑1336, but no further details on exploitation, patches, or technical specifics are provided.

    0000083
    1 followersView on X

Explore more