PT-2024-7645 · WordPress · Ai Power: Complete Ai Pack

Dale Mavers

+1

·

Published

2024-10-26

·

Updated

2024-11-06

·

CVE-2024-10392

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions AI Power: Complete AI Pack plugin for WordPress versions 1.8.89 and earlier
Description The issue is related to arbitrary file uploads due to missing file type validation in the handle image upload function. This allows unauthenticated attackers to upload arbitrary files on the affected site's server, which may make remote code execution possible. The estimated number of potentially affected devices worldwide is over 10,000 sites.
Recommendations For versions 1.8.89 and earlier, update to the latest version to mitigate the risk of remote code execution. As a temporary workaround, consider disabling the handle image upload function until a patch is available. Restrict access to the vulnerable plugin to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2024-09086
CVE-2024-10392

Affected Products

Ai Power: Complete Ai Pack