
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12156 is a missing authorization vulnerability in the "Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT) All in One" plugin for WordPress. It affects plugin versions 2.0.7 through 2.2.6 and allows authenticated attackers with Subscriber-level access or higher to create and publish arbitrary posts due to a missing capability check on the save_post_data() function. The vulnerability was published on November 4, 2025, and carries a CVSS v3.1 base score of 4.3 (Medium), assigned by Wordfence (Wordfence).
The root cause is classified as CWE-862 (Missing Authorization). The save_post_data() function in the affected plugin versions does not perform a capability check before allowing post creation and publication, meaning any authenticated user — even those with minimal privileges such as Subscriber — can invoke this function over the network without any additional conditions. The attack vector is network-based, requires low privileges, no user interaction, and low attack complexity (Wordfence).
Successful exploitation allows authenticated low-privileged users to create and publish arbitrary posts on the affected WordPress site, impacting content integrity. There is no confidentiality or availability impact, and the scope is limited to the affected WordPress installation. While not directly enabling remote code execution or data theft, abuse could facilitate spam publishing, SEO manipulation, or content defacement on vulnerable sites (Wordfence).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-12156. The EPSS score is approximately 0.026% (0.000260), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum a valid Subscriber-level account on the target WordPress site (Wordfence).
/wp-content/plugins/ai-auto-tool/readme.txt.wp-admin/admin-ajax.php) or the relevant REST route that triggers save_post_data(), supplying arbitrary post content and publication parameters.wp-admin/admin-ajax.php or plugin-specific endpoints from Subscriber-level accounts, particularly with actions related to save_post_data.wp_posts database table for posts authored by Subscriber-level users with unusual content or publication timestamps.Users should update the "Ai Auto Tool Content Writing Assistant" plugin to a version beyond 2.2.6 that includes a proper capability check in the save_post_data() function. Until a patched version is available or confirmed, site administrators should consider deactivating the plugin or restricting user registration to prevent untrusted Subscriber-level accounts. Monitoring WordPress user roles and limiting open registration are recommended interim measures (Wordfence, WordPress Plugin).
Wordfence included CVE-2025-12156 in their weekly WordPress vulnerability report for November 3–9, 2025, as part of routine disclosure coverage (Wordfence Blog). No significant broader media coverage, vendor statements beyond the Wordfence advisory, or notable researcher commentary has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."