Arbitrary File Upload Vulnerability in AI Engine: Chatbots Plugin for WordPress
CVE-2024-0699
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 February 2024
What is CVE-2024-0699?
The AI Engine: Chatbots, Generators, Assistants, GPT 4 plugin for WordPress suffers from a vulnerability due to inadequate file type validation in the 'add_image_from_url' function. This affects all versions up to and including 2.1.4, allowing authenticated users with Editor access or higher to upload arbitrary files to the server. This unauthorized file upload could lead to significant security risks, including the possibility of remote code execution, compromising the integrity and availability of the affected website.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! * <= 2.1.4
References
EPSS Score
7% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved