Junglewise Threat Intelligence

CVE-2025-62154: recorp AI Content Writing Assistant broken access control

CVE-2025-62154 · Severity: medium · CVSS 4.3 · Published 2025-12-31

Executive brief

The recorp AI Content Writing Assistant is a WordPress plugin that provides AI-powered writing, chatbot, and image generation features. A broken access control vulnerability allows unauthorized users with contributor-level access to view or perform actions they should not be permitted to, potentially exposing sensitive data or functionality intended only for administrators.

Technical details

This is a broken access control (missing authorization) vulnerability affecting the AI Content Writing Assistant WordPress plugin. The vulnerability stems from incorrectly configured access control security levels that fail to properly verify user permissions before allowing access to protected pages or actions. An attacker with contributor-level WordPress privileges can exploit this to bypass authorization checks and access functionality or data restricted to higher privilege levels. The vulnerability affects versions up to and including 1.1.7, with no official patch currently available as of the advisory publication date.

Affected products

  • recorp AI Content Writing Assistant through 1.1.7

Timeline

  • 2025-01-31: disclosed: Published by Patchstack
  • 2025-11-01: other: Reported to Patchstack

References