PT-2025-44943 · Aitool+1 · Ai Auto Tool Content Writing Assistant (Gemini Writer+1

·

CVE-2025-12156

·

Published

2025-11-03

·

Updated

2025-11-04

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress versions 2.0.7 through 2.3.0
Description Unauthorized modification of data is possible due to a missing capability check in the save post data() function. This allows authenticated attackers with Subscriber-level access or higher to create and publish arbitrary posts.
Recommendations Update the plugin to a version later than 2.3.0. As a temporary mitigation, restrict access to the save post data() function.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-12156

Affected Products

Ai Auto Tool Content Writing Assistant (Gemini Writer
Ai-Auto-Tool