Unauthorized Access Vulnerability in AI Post Generator Plugin for WordPress
CVE-2024-1850
6.3MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 9 April 2024
Summary
The AI Post Generator | AutoWriter plugin for WordPress has a vulnerability that allows unauthorized access, modification, or deletion of posts. This flaw arises from a missing capability check on functions associated with AJAX actions across all versions up to and including 3.3. Consequently, authenticated attackers with subscriber access or higher can exploit this vulnerability to view all posts created with the plugin, even those that are unpublished. They can also create new posts, publish unpublished content, and delete existing posts without proper authorization.
Affected Version(s)
AI Post Generator | AutoWriter * <= 3.3
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lucio Sá