CVE-2024-29100: WordPress AI Engine plugin <= 2.1.4 - Arbitrary File Upload vulnerability
Published Mar 28, 2024
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.
Affected Software
3 affected components
Jordy Meow AI Engine: ChatGPT Chatbot<=2.1.4
WordPress AI Engine plugin<=2.1.4
Meowapps Ai Engine Wordpress<2.1.5
Remediation
Information
Update to 2.1.5 or a higher version.
Event History
Mar 28, 2024
CVE Published
via MITRE·05:10 AM
Data Sourced
via MITRE·05:10 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29100?
CVE-2024-29100 is categorized as a high-severity vulnerability due to its potential for unrestricted file uploads.
2
How do I fix CVE-2024-29100?
To mitigate CVE-2024-29100, upgrade the Jordy Meow AI Engine: ChatGPT Chatbot to version 2.1.5 or later.
3
What is the impact of CVE-2024-29100?
CVE-2024-29100 allows attackers to upload malicious files, which can lead to remote code execution or system compromise.
4
Which versions are affected by CVE-2024-29100?
CVE-2024-29100 affects versions of the AI Engine: ChatGPT Chatbot up to and including 2.1.4.
5
Is the WordPress AI Engine plugin affected by CVE-2024-29100?
Yes, the WordPress AI Engine plugin versions up to and including 2.1.4 are also affected by CVE-2024-29100.