CVE Database /
CVE-2024-10392
CVE · Critical
CVE-2024-10392 — AI Puffer – Chat. Create. Automate. (formerly AI Power) [gpt3-ai-content-generator] < 1.8.90
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-10392
|
AI Puffer – Chat. Create. Automate. (formerly AI Power) [gpt3-ai-content-generator] < 1.8.90 |
Unrestricted Upload of File with Dangerous Type |
Critical
9.8
|
< 1.8.90
|
1.8.90 |
2024-10-30 |
—
|
CVE-2024-10392
The AI Puffer plugin for WordPress (previously called AI Power) contains a flaw in its image upload handler that fails to properly validate file types, allowing unauthenticated users to upload any type of file to the server. This vulnerability exists in versions 1.8.89 and earlier and could enable attackers to execute arbitrary code on affected WordPress installations. The issue stems from insufficient validation checks in the file upload processing function.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings