What happened
NVD published CVE-2026-97305 (via Patchstack) on 2026-10-05 for an Authorization Bypass Through User-Controlled Key / IDOR in the Hyve Lite AI Chatbot WordPress plugin through 2.0.2, fixed in 2.0.3. The user-controlled key allows bypassing incorrectly configured access-control levels; CISA SSVC marks it automatable.
Why it matters
AI chatbot plugins are frequently internet-facing; an IDOR here lets unauthenticated callers step outside the chatbot's authorization boundary to reach data they should not see, and it is trivially automatable against any exposure — a representative low-CVSS catalogued WordPress AI-plugin flaw worth keeping on the radar for site owners.
Attack vector
An unauthenticated remote attacker exploits insecure direct object references in the chatbot plugin's access control to reach objects/users/records through user-controlled identifiers, bypassing the intended authorization levels (CVSS 6.9 v4.0).
Affected systems
WordPress themeisle/hyve-lite AI Chatbot plugin ≤ 2.0.2
Mitigation
Upgrade hyve-lite to 2.0.3 (Patchstack advisory: https://patchstack.com/database/wordpress/plugin/hyve-lite/vulnerability/wordpress-ai-chatbot-for-wordpress-hyve-lite-plugin-2-0-2-insecure-direct-object-references-idor-vulnerability).