Vulnerability  ·  2026-10-06

Themeisle Hyve Lite AI Chatbot for WordPress: IDOR authorization bypass exposes data via user-controlled keys (CVE-2026-97305)

VulnerabilityMedium impactGlobalCVE-2026-97305
NVD published CVE-2026-97305 (via Patchstack) on 2026-10-05 for an Authorization Bypass Through User-Controlled Key / IDOR in the Hyve Lite AI Chatbot WordPress plugin through 2.0.2, fixed in 2.0.3. The user-controlled key allows bypassing incorrectly configured access-control levels; CISA SSVC marks it automatable.
AI chatbot plugins are frequently internet-facing; an IDOR here lets unauthenticated callers step outside the chatbot's authorization boundary to reach data they should not see, and it is trivially automatable against any exposure — a representative low-CVSS catalogued WordPress AI-plugin flaw worth keeping on the radar for site owners.
An unauthenticated remote attacker exploits insecure direct object references in the chatbot plugin's access control to reach objects/users/records through user-controlled identifiers, bypassing the intended authorization levels (CVSS 6.9 v4.0).
WordPress themeisle/hyve-lite AI Chatbot plugin ≤ 2.0.2
Upgrade hyve-lite to 2.0.3 (Patchstack advisory: https://patchstack.com/database/wordpress/plugin/hyve-lite/vulnerability/wordpress-ai-chatbot-for-wordpress-hyve-lite-plugin-2-0-2-insecure-direct-object-references-idor-vulnerability).
NVD (cite)Patchstack advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →