Extension WordPress

Vulnérabilités AI Puffer – Chat. Create. Automate. (formerly AI Power)

Cette page rassemble les failles publiées pour AI Puffer – Chat. Create. Automate. (formerly AI Power), leurs plages de versions affectées et les correctifs signalés dans la base locale.

12Vulnérabilités
1Critiques
12Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de AI Puffer – Chat. Create. Automate. (formerly AI Power)

12 fiches

CVE-2024-13362 Moyenne · 6,1
AI Puffer – Chat. Create. Automate. (formerly AI Power)

Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

Versions affectées

*-1.8.99

Correctif

2.3.17

Publication

30/04/2026

CVE-2025-47470 Moyenne · 4,3
AI Puffer – Chat. Create. Automate. (formerly AI Power)

GPT3 AI Content Writer <= 1.9.14 – Cross-Site Request Forgery

The GPT3 AI Content Writer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.14. This is due to missing or incorrect nonce validation on the wpaicg_generate_custom_prompt() function. This makes it possible…

Versions affectées

*-1.9.14

Correctif

1.9.15

Publication

07/05/2025

CVE-2025-0429 Élevée · 7,2
AI Puffer – Chat. Create. Automate. (formerly AI Power)

AI Power: Complete AI Pack <= 1.8.96 – Authenticated (Admin+) PHP Object Injection via wpaicg_export_ai_forms

The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_ai_forms() function. This allows authenticated…

Versions affectées

*-1.8.96

Correctif

1.8.97

Publication

21/01/2025

CVE-2025-0428 Élevée · 7,2
AI Puffer – Chat. Create. Automate. (formerly AI Power)

AI Power: Complete AI Pack <= 1.8.96 – Authenticated (Admin+) PHP Object Injection via wpaicg_export_prompts

The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_prompts function. This allows authenticated…

Versions affectées

*-1.8.96

Correctif

1.8.97

Publication

21/01/2025

CVE-2024-13360 Moyenne · 5,4
AI Puffer – Chat. Create. Automate. (formerly AI Power)

AI Power: Complete AI Pack <= 1.8.96 – Authenticated (Subscriber+) Server-Side Request Forgery

The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.8.96 via the wpaicg_troubleshoot_add_vector(). This makes it possible for authenticated attackers, with subscriber-level access and above,…

Versions affectées

*-1.8.96

Correctif

1.8.97

Publication

21/01/2025

CVE-2024-13361 Moyenne · 6,3
AI Puffer – Chat. Create. Automate. (formerly AI Power)

AI Power: Complete AI Pack <= 1.8.96 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution

The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpaicg_save_image_media function in all versions up to, and including, 1.8.96. This makes it possible for authenticated…

Versions affectées

*-1.8.96

Correctif

1.8.97

Publication

21/01/2025

CVE-2024-10392 Critique · 9,8
AI Puffer – Chat. Create. Automate. (formerly AI Power)

AI Power: Complete AI Pack <= 1.8.89 – Unauthenticated Arbitrary File Upload

The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_image_upload' function in all versions up to, and including, 1.8.89. This makes it possible for…

Versions affectées

*-1.8.89

Correctif

1.8.90

Publication

30/10/2024

CVE-2024-37465 Moyenne · 6,4
AI Puffer – Chat. Create. Automate. (formerly AI Power)

GPT3 AI Content Writer <= 1.8.66 – Authenticated (Contributor+) Stored Cross-Site Scripting

The GPT3 AI Content Writer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.66 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-1.8.66

Correctif

1.8.67

Publication

01/07/2024

CVE-2023-51528 Moyenne · 4,3
AI Puffer – Chat. Create. Automate. (formerly AI Power)

GPT3 AI Content Writer <= 1.8.12 – Cross-Site Request Forgery

The GPT3 AI Content Writer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.12. This is due to missing or incorrect nonce validation on the wpaicg_export_logs_callback() function. This makes it possible…

Versions affectées

*-1.8.12

Correctif

1.8.13

Publication

27/12/2023

CVE-2023-51527 Moyenne · 5,3
AI Puffer – Chat. Create. Automate. (formerly AI Power)

AI Power: Complete AI Pack – Powered by GPT-4 <= 1.8.1 – Missing Authorization to Sensitive Data Exposure

The AI Power: Complete AI Pack – Powered by GPT-4 plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpaicg_export_logs_callback() function in all versions up to, and including, 1.8.2. This makes…

Versions affectées

*-1.8.2

Correctif

1.8.3

Publication

27/12/2023

CVE-2023-33999 Moyenne · 6,1
AI Puffer – Chat. Create. Automate. (formerly AI Power)

Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

1.4.10-1.7.37

Correctif

1.7.38

Publication

18/07/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités