CVE-2024-34440: WordPress AI Engine plugin <= 2.2.63 - Auth. Arbitrary File Upload vulnerability
Published May 13, 2024
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.2.63.
Affected Software
3 affected components
Jordy Meow AI Engine: ChatGPT Chatbot<=2.2.63
WordPress AI Engine plugin<=2.2.63
Meowapps Ai Engine Wordpress<2.2.70
Remediation
Information
Update to 2.2.70 or a higher version.
Event History
May 13, 2024
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
RemedyDescriptionSeverityWeakness
May 14, 2024
Data Sourced
via NVD·03:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-34440?
CVE-2024-34440 is a high-severity vulnerability due to the unrestricted file upload flaw.
2
How do I fix CVE-2024-34440?
To fix CVE-2024-34440, upgrade the Jordy Meow AI Engine: ChatGPT Chatbot to version 2.2.64 or higher.
3
Which versions are affected by CVE-2024-34440?
CVE-2024-34440 affects versions of Jordy Meow AI Engine: ChatGPT Chatbot up to and including 2.2.63.
4
What is the impact of CVE-2024-34440?
The impact of CVE-2024-34440 includes potential unauthorized access and execution of dangerous file uploads.
5
Is CVE-2024-34440 relevant to WordPress AI Engine plugins?
Yes, CVE-2024-34440 also affects the WordPress AI Engine plugin up to and including version 2.2.63.