Authorization Bypass Through User-Controlled Key vulnerability in Themeisle AI Chatbot for WordPress – Hyve Lite hyve-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Chatbot for WordPress – Hyve Lite: from n/a through 2.0.2.
Advisories

No advisories yet.

Fixes

Solution

Update the WordPress AI Chatbot for WordPress – Hyve Lite plugin to the latest available version (at least 2.0.3).


Workaround

No workaround given by the vendor.

History

Mon, 05 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key vulnerability in Themeisle AI Chatbot for WordPress – Hyve Lite hyve-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Chatbot for WordPress – Hyve Lite: from n/a through 2.0.2.
Title WordPress AI Chatbot for WordPress – Hyve Lite plugin <= 2.0.2 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T18:45:13.106Z

Reserved: 2026-09-24T10:23:27.498Z

Link: CVE-2026-97305

cve-icon Vulnrichment

Updated: 2026-10-05T18:45:08.678Z

cve-icon NVD

Status : Received

Published: 2026-10-05T19:17:27.527

Modified: 2026-10-05T19:17:27.527

Link: CVE-2026-97305

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T20:45:18Z

Weaknesses