Extension WordPress
Vulnérabilités AI Engine – The Chatbot, AI Framework & MCP for WordPress, page 2
Cette page rassemble les failles publiées pour AI Engine – The Chatbot, AI Framework & MCP for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de AI Engine – The Chatbot, AI Framework & MCP for WordPress
24 fiches
AI Engine <= 2.2.0 – Unauthenticated Stored Cross-Site Scripting
The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI chat data when discussion tracking is enabled in all versions up to, and including, 2.2.0 due…
*-2.2.0
2.2.1
01/03/2024
AI Engine <= 2.1.4 – Authenticated(Editor+) Arbitrary File Upload via add_image_from_url
The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_image_from_url' function in all versions up to, and including, 2.1.4. This…
*-2.1.4
2.1.5
18/01/2024
AI Engine: ChatGPT Chatbot <= 1.9.98 – Unauthenticated Arbitrary File Upload via rest_upload
The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'rest_upload' function in all versions up to, and including, 1.9.98. This…
*-1.9.98
1.9.99
09/01/2024
AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable <= 1.6.82 – Authenticated (Admin+) Stored Cross-Site Scripting
The AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in versions up to, and including, 1.6.82 due to insufficient input sanitization and…
[*, 1.6.83)
1.6.83
19/05/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.