Input validation vulnerability in AI Content Pipelines: Content Engine + Analytics 1.6

The AI Content Pipelines plugin for WordPress can be easily hacked by malicious individuals through uploading SVG files. This vulnerability affects all versions up to 1.6 and is caused by not properly checking and filtering the input and output. This allows attackers who have at least Author-level access to insert harmful web scripts into pages, which will activate whenever anyone opens the SVG file.

Detected in:

AI Content Pipelines: Content Engine + Analytics open vulnerable versions: >= * <= 1.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.