CVE · Medium

CVE-2024-13360 — AI Puffer – Chat. Create. Automate. (formerly AI Power) [gpt3-ai-content-generator] < 1.8.97

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13360 AI Puffer – Chat. Create. Automate. (formerly AI Power) [gpt3-ai-content-generator] < 1.8.97 Server-Side Request Forgery (SSRF) Medium 5.4 < 1.8.97 1.8.97 2025-01-21

CVE-2024-13360

The AI Power: Complete AI Pack WordPress plugin contains a server-side request forgery vulnerability in the wpaicg_troubleshoot_add_vector() function affecting versions up to and including 1.8.96, allowing authenticated users with subscriber privileges or higher to send arbitrary web requests from the server to external or internal targets, potentially enabling unauthorized access to or modification of data from internal services.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.