{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/ai-chatbot--workflow-automation/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-6639"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AI Chatbot \u0026 Workflow Automation"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["AIWU"],"content_html":"\u003cp\u003eThe AI Chatbot \u0026amp; Workflow Automation plugin for WordPress (versions 1.4.6 and below) contains a critical security flaw resulting in sensitive information exposure. The vulnerability exists within the \u003ccode\u003egetCurrentTaskResults()\u003c/code\u003e method located in \u003ccode\u003emodules/workspace/controller.php\u003c/code\u003e, which fails to implement necessary authentication or authorization checks.\u003c/p\u003e\n\u003cp\u003eThe plugin registers AJAX actions using the \u003ccode\u003ewp_ajax_nopriv_\u003c/code\u003e hook, making them globally accessible to unauthenticated users. Furthermore, the method is excluded from the plugin's \u003ccode\u003egetNoncedMethods()\u003c/code\u003e array, and the base \u003ccode\u003egetPermissions()\u003c/code\u003e check returns an empty array. Attackers can exploit this by sending crafted AJAX requests to the vulnerable endpoint, iterating through task IDs to retrieve stored task objects. These objects contain plaintext OpenAI API keys, AI prompts, keywords, and specific model configuration parameters. This exposure allows threat actors to hijack third-party AI services linked to the compromised WordPress installation and potentially leverage the leaked configuration to refine further downstream attacks.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site running the AI Chatbot \u0026amp; Workflow Automation plugin.\u003c/li\u003e\n\u003cli\u003eAttacker probes the site to determine if the \u003ccode\u003ewp-admin/admin-ajax.php\u003c/code\u003e endpoint is accessible for plugin-specific actions.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a series of HTTP GET or POST requests directed at the \u003ccode\u003egetCurrentTaskResults\u003c/code\u003e AJAX action.\u003c/li\u003e\n\u003cli\u003eAttacker performs sequential enumeration of task IDs (e.g., iterating integer values) within the request parameters.\u003c/li\u003e\n\u003cli\u003eThe plugin processes the requests, bypassing authentication due to the use of \u003ccode\u003ewp_ajax_nopriv_\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe plugin retrieves sensitive task data, including plaintext API keys, from the backend database.\u003c/li\u003e\n\u003cli\u003eThe sensitive data is returned to the attacker in a JSON-formatted response.\u003c/li\u003e\n\u003cli\u003eAttacker parses the JSON response to harvest OpenAI API keys and configuration details for unauthorized usage.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to the unauthorized disclosure of sensitive plugin configuration data, specifically plaintext OpenAI API keys. In an enterprise or high-traffic environment, this results in the theft of proprietary AI prompts and costly API credit theft. Unauthorized access to these keys could allow attackers to perform actions on behalf of the organization within the associated AI service platform.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the AI Chatbot \u0026amp; Workflow Automation plugin to a version beyond 1.4.6 immediately.\u003c/li\u003e\n\u003cli\u003eAudit access logs for high-frequency requests to \u003ccode\u003eadmin-ajax.php\u003c/code\u003e containing the \u003ccode\u003eaction\u003c/code\u003e parameter associated with \u003ccode\u003egetCurrentTaskResults\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eIf the plugin cannot be updated, disable the plugin until a patch is applied.\u003c/li\u003e\n\u003cli\u003eRevoke and rotate any OpenAI API keys stored in WordPress plugins that were exposed or suspected of being accessed by unauthorized parties.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T09:16:45Z","date_published":"2026-08-05T09:16:45Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-6639/","summary":"An authentication bypass vulnerability in the AI Chatbot \u0026 Workflow Automation WordPress plugin allows unauthenticated attackers to exfiltrate API keys and task configurations via sequential ID enumeration.","title":"Unauthenticated Sensitive Information Exposure in WordPress AI Chatbot Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-6639/"}],"language":"en","title":"CraftedSignal Threat Feed - AI Chatbot \u0026 Workflow Automation","version":"https://jsonfeed.org/version/1.1"}