PT-2025-2132 · WordPress · Ai Power: Complete Ai Pack

Khayal Farzaliyev

+1

·

Published

2025-01-22

·

Updated

2025-01-23

·

CVE-2024-13360

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AI Power: Complete AI Pack plugin for WordPress versions up to, and including, 1.8.96
Description The issue allows authenticated attackers with subscriber-level access and above to make web requests to arbitrary locations originating from the web application. This can be used to query and modify information from internal services through the wpaicg troubleshoot add vector() function.
Recommendations For versions up to, and including, 1.8.96, consider disabling the wpaicg troubleshoot add vector() function as a temporary workaround until a patch is available. Restrict access to the vulnerable component to minimize the risk of exploitation. Update to a version higher than 1.8.96 when available.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-13360

Affected Products

Ai Power: Complete Ai Pack