PT-2024-37280 · WordPress · The Aiomatic

István Márton

·

Published

2024-07-27

·

Updated

2025-08-08

·

CVE-2024-5969

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: The AIomatic - Automatic AI Content Writer for WordPress versions up to, and including, 2.0.5
Description: The issue is due to insufficient limitations on the email recipient and the content in the aiomatic send email function, which are reachable via AJAX. This allows unauthenticated attackers to send emails with any content to any recipient.
Recommendations: For versions up to, and including, 2.0.5, consider disabling the aiomatic send email function until a patch is available to prevent exploitation. Restrict access to AJAX endpoints related to this function to minimize the risk of unauthorized email sending.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-5969

Affected Products

The Aiomatic