CVE-2024-5969: AIomatic - Automatic AI Content Writer <= 2.0.5 - Unauthenticated Arbitrary Email Sending
The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is due to insufficient limitations on the email recipient and the content in the 'aiomaticsendemail' function which are reachable via AJAX. This makes it possible for unauthenticated attackers to send emails with any content to any recipient.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5969?
CVE-2024-5969 has a high severity rating due to its potential for arbitrary email sending and exposure to malicious actors.
How do I fix CVE-2024-5969?
To fix CVE-2024-5969, update the AIomatic plugin to version 2.0.6 or later, which addresses the vulnerability.
What versions of AIomatic are affected by CVE-2024-5969?
CVE-2024-5969 affects all versions of AIomatic up to and including 2.0.5.
What type of vulnerability is CVE-2024-5969?
CVE-2024-5969 is an arbitrary email sending vulnerability due to insufficient validation in the email sending function.
Can CVE-2024-5969 allow for spam or phishing attacks?
Yes, CVE-2024-5969 can be exploited to send spam or phishing emails by leveraging the arbitrary email sending functionality.