The AI Puffer plugin for WordPress has a vulnerability that allows authenticated attackers with subscriber-level access to modify global site-wide semantic search settings. This is due to a missing authorization check in the plugin. The vulnerability can impact site functionality and user experience. Defenders should assess exposure and prioritize verification of the plugin version and access controls. Th [truncated]
The AI Puffer plugin for WordPress, versions up to and including 2.4.89, is vulnerable to authorization bypass. This vulnerability allows authenticated attackers with subscriber-level access and above to modify global plugin settings, potentially impacting plugin functionality and user data. The vulnerability arises from the plugin's improper verification of user authorization, enabling attackers to alter [truncated]