Extension WordPress
Vulnérabilités Aiomatic – Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit
Cette page rassemble les failles publiées pour Aiomatic – Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Aiomatic – Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit
5 fiches
Aiomatic – AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.5.0 – Authenticated (Subscriber+) Arbitrary File Upload
The Aiomatic – Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aiomatic_image_editor_ajax_submit' function in all…
*-2.5.0
2.5.1
23/06/2025
Aiomatic – AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.8 – Missing Authorization to Authenticated (Contributor+) Arbitrary File Upload
The Aiomatic – Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aiomatic_generate_featured_image' function in all…
*-2.3.8
2.3.9
07/03/2025
Aiomatic – AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.6 – Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions
The Aiomatic – Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability checks on multiple…
*-2.3.6
2.3.7
07/03/2025
AIomatic – Automatic AI Content Writer <= 2.0.5 – Unauthenticated Arbitrary Email Sending
The AIomatic – Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is due to insufficient limitations on the email recipient and the content in the…
*-2.0.5
2.0.6
14/06/2024
Aiomatic <= 1.9.3 – Missing Authorization
The Aiomatic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.9.3. This makes it possible for authenticated attackers, with subscriber-level access and above,…
*-1.9.3
1.9.4
07/05/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.