CVE-2024-31351

CRITICAL

Copymatic - AI Content Writer & Generator <= 1.6 - Unauthenticated Arbitrary File Upload

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-31351. PoCs published by KTN1990.

AI-analyzed exploit summary The repository claims to exploit CVE-2024-31351 but lacks actual exploit code, instead directing users to external contacts (Telegram) and promoting a paid service ('Megatron'). No technical details or functional PoC are provided.

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Copymatic Copymatic – AI Content Writer & Generator.This issue affects Copymatic – AI Content Writer & Generator: from n/a through 1.6.

Exploits (1)

nomisec SUSPICIOUS
by KTN1990 · poc
https://github.com/KTN1990/CVE-2024-31351_wordpress_exploit

The repository claims to exploit CVE-2024-31351 but lacks actual exploit code, instead directing users to external contacts (Telegram) and promoting a paid service ('Megatron'). No technical details or functional PoC are provided.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: Copymatic – AI Content Writer & Generator <= 1.6
No auth needed
Prerequisites: none provided
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 10.0
EPSS 0.0162
EPSS Percentile 73.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (2)
copymatic/copymatic < 1.7
Copymatic/Copymatic – AI Content Writer & Generator < 1.6
Published May 17, 2024
Tracked Since Feb 18, 2026