Unauthorized Access Vulnerability in AI Post Generator Plugin for WordPress
CVE-2024-1850
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 9 April 2024
What is CVE-2024-1850?
The AI Post Generator | AutoWriter plugin for WordPress has a vulnerability that allows unauthorized access, modification, or deletion of posts. This flaw arises from a missing capability check on functions associated with AJAX actions across all versions up to and including 3.3. Consequently, authenticated attackers with subscriber access or higher can exploit this vulnerability to view all posts created with the plugin, even those that are unpublished. They can also create new posts, publish unpublished content, and delete existing posts without proper authorization.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AI Post Generator | AutoWriter * <= 3.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved