First published: Wed Oct 23 2024(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in Dogu Pekgoz AI Image Generator for Your Content & Featured Images – AI Postpix allows Upload a Web Shell to a Web Server.This issue affects AI Image Generator for Your Content & Featured Images – AI Postpix: from n/a through 1.1.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress AI Postpix | <=1.1.8 | |
Dogu Pekgoz AI Postpix | <=1.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49671 is considered a high-risk vulnerability due to its potential for unrestricted file uploads leading to web shell access.
To fix CVE-2024-49671, update the Dogu Pekgoz AI Postpix plugin to version 1.1.9 or later.
CVE-2024-49671 affects all versions of Dogu Pekgoz AI Postpix and WordPress AI Postpix up to and including version 1.1.8.
Not addressing CVE-2024-49671 poses a significant risk as it allows attackers to upload malicious files and potentially take control of the web server.
Yes, CVE-2024-49671 can be exploited remotely, allowing attackers to exploit the vulnerability without physical access to the server.