The Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_post_data() function in versions 2.0.7 to 2.2.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create and publish arbitrary posts.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aitool
Aitool ai Auto Tool Content Writing Assistant Wordpress Wordpress wordpress |
|
| Vendors & Products |
Aitool
Aitool ai Auto Tool Content Writing Assistant Wordpress Wordpress wordpress |
Tue, 04 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Nov 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_post_data() function in versions 2.0.7 to 2.2.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create and publish arbitrary posts. | |
| Title | Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One 2.0.7 - 2.2.6 - Missing Authorization to Authenticated (Subscriber+) Post Creation | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-11-04T04:27:18.698Z
Updated: 2025-11-04T16:08:38.677Z
Reserved: 2025-10-24T13:12:00.611Z
Link: CVE-2025-12156
Updated: 2025-11-04T16:08:36.163Z
Status : Awaiting Analysis
Published: 2025-11-04T05:16:08.120
Modified: 2025-11-04T15:40:45.533
Link: CVE-2025-12156
No data.