Unauthorized Access Vulnerability in AI Post Generator Plugin for WordPress
CVE-2024-1850

6.3MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
9 April 2024

Summary

The AI Post Generator | AutoWriter plugin for WordPress has a vulnerability that allows unauthorized access, modification, or deletion of posts. This flaw arises from a missing capability check on functions associated with AJAX actions across all versions up to and including 3.3. Consequently, authenticated attackers with subscriber access or higher can exploit this vulnerability to view all posts created with the plugin, even those that are unpublished. They can also create new posts, publish unpublished content, and delete existing posts without proper authorization.

Affected Version(s)

AI Post Generator | AutoWriter * <= 3.3

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lucio Sá
.