nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-10392 CVE-2024-10392
CRITICAL
AI Power: Complete AI Pack <= 1.8.89 - Unauthenticated Arbitrary File Upload
Record summary
CVE-2024-10392 has a selected CVSS score of 9.8 (critical).
Description
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_image_upload' function in all versions up to, and including, 1.8.89. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 30, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 31, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
AI Power: Complete AI Pack plugin for WordPressBrowse AI Power / AI Power: Complete AI Pack plugin for WordPress | VulnCheck | Version data not supplied | |
aipowerBrowse aipower / aipowerDefault status: unknown | CVE List | Through 1.8.89 | affected |
AI Puffer – Your AI engine for WordPress (formerly AI Power)Browse senols / AI Puffer – Your AI engine for WordPress (formerly AI Power)Default status: unaffected | CVE List | Through 1.8.89 | affected |
References
3plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3176122/gpt3-ai-content-generator wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/cd8a45c9-ca48-4ea6-b34e-f05206f16155?source=cve