CVE-2024-29100: WordPress AI Engine plugin <= 2.1.4 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jordy Meow AI Engine: ChatGPT Chatbotto a version that resolves this vulnerability.Fixed in 2.1.5
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29100?
CVE-2024-29100 is categorized as a high-severity vulnerability due to its potential for unrestricted file uploads.
How do I fix CVE-2024-29100?
To mitigate CVE-2024-29100, upgrade the Jordy Meow AI Engine: ChatGPT Chatbot to version 2.1.5 or later.
What is the impact of CVE-2024-29100?
CVE-2024-29100 allows attackers to upload malicious files, which can lead to remote code execution or system compromise.
Which versions are affected by CVE-2024-29100?
CVE-2024-29100 affects versions of the AI Engine: ChatGPT Chatbot up to and including 2.1.4.
Is the WordPress AI Engine plugin affected by CVE-2024-29100?
Yes, the WordPress AI Engine plugin versions up to and including 2.1.4 are also affected by CVE-2024-29100.