CVE Database /
CVE-2024-34440
CVE · High
CVE-2024-34440 — AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 2.2.70
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-34440
|
AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 2.2.70 |
Unrestricted Upload of File with Dangerous Type |
High
7.2
|
< 2.2.70
|
2.2.70 |
2024-05-07 |
—
|
CVE-2024-34440
The AI Engine plugin for WordPress contains a vulnerability in versions up to 2.2.63 that allows authenticated users with Editor privileges or higher to upload files without proper type checking. This weakness could enable attackers to upload malicious files to the server, potentially leading to remote code execution on the affected website.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings