CVE · Critical

CVE-2024-10392 — AI Puffer – Chat. Create. Automate. (formerly AI Power) [gpt3-ai-content-generator] < 1.8.90

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10392 AI Puffer – Chat. Create. Automate. (formerly AI Power) [gpt3-ai-content-generator] < 1.8.90 Unrestricted Upload of File with Dangerous Type Critical 9.8 < 1.8.90 1.8.90 2024-10-30

CVE-2024-10392

The AI Puffer plugin for WordPress (previously called AI Power) contains a flaw in its image upload handler that fails to properly validate file types, allowing unauthenticated users to upload any type of file to the server. This vulnerability exists in versions 1.8.89 and earlier and could enable attackers to execute arbitrary code on affected WordPress installations. The issue stems from insufficient validation checks in the file upload processing function.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.