CVE-2025-62154
Description
Missing Authorization vulnerability in recorp AI Content Writing Assistant (Content Writer, ChatGPT, Image Generator) All in One ai-content-writing-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Content Writing Assistant (Content Writer, ChatGPT, Image Generator) All in One: from n/a through <= 1.1.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A missing authorization vulnerability in the WordPress AI Content Writing Assistant plugin allows unauthenticated attackers to exploit incorrectly configured access controls.
The AI Content Writing Assistant (Content Writer, ChatGPT, Image Generator) All in One plugin for WordPress, versions 1.1.7 and earlier, contains a missing authorization vulnerability [1]. This means that certain functions or endpoints lack proper access control checks, allowing exploitation of incorrectly configured access control security levels [Description].
The vulnerability is classified as a broken access control issue, where missing authorization, authentication, or nonce token checks can enable an unprivileged user (or possibly an unauthenticated attacker) to execute higher-privileged actions [1]. No authentication is required for exploitation, making the attack surface significant for any site running the vulnerable plugin [1].
As a medium-severity issue (CVSS 4.3), this vulnerability is noted to be used in mass-exploit campaigns, allowing attackers to target thousands of websites simultaneously [1]. The impact includes potential unauthorized modifications, data exposure, or other actions that should be restricted to authorized users [1].
Users are strongly advised to update the plugin immediately if a patched version becomes available. If an update is not possible, contacting the hosting provider or web developer for mitigation steps is recommended [1]. No other workarounds are detailed in the reference.
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <= 1.1.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.