CVE-2024-0699: AI Engine <= 2.1.4 - Authenticated(Editor+) Arbitrary File Upload via add_image_from_url
The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'addimagefromurl' function in all versions up to, and including, 2.1.4. This makes it possible for authenticated attackers, with Editor access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE-2024-29100 is likely a duplicate of this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0699?
CVE-2024-0699 is considered a high severity vulnerability due to the potential for arbitrary file uploads.
How do I fix CVE-2024-0699?
To fix CVE-2024-0699, users should update the AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin to version 2.1.5 or later.
Who is affected by CVE-2024-0699?
Authenticated users of the AI Engine plugin for WordPress versions up to and including 2.1.4 are affected by CVE-2024-0699.
What types of attacks can CVE-2024-0699 enable?
CVE-2024-0699 can enable authenticated attackers to upload malicious files to the server.
Is there a workaround for CVE-2024-0699?
Currently, there is no known workaround for CVE-2024-0699 other than updating to the latest version of the plugin.