Input validation vulnerability in Aiomatic – Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit 2.5.0

The Aiomatic plugin for WordPress, which automatically generates and edits AI content using GPT-3 and GPT-4, has a vulnerability that allows attackers to upload any type of file without restriction. This can be done by users with at least Subscriber-level access, and it could potentially allow for remote code execution on the affected website’s server. To exploit this vulnerability, an attacker would need to enter a value for the Stability.AI API key, which can be any value.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.