Extension WordPress
Vulnérabilités AI Puffer – Chat. Create. Automate. (formerly AI Power)
Cette page rassemble les failles publiées pour AI Puffer – Chat. Create. Automate. (formerly AI Power), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de AI Puffer – Chat. Create. Automate. (formerly AI Power)
12 fiches
Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-1.8.99
2.3.17
30/04/2026
GPT3 AI Content Writer <= 1.9.14 – Cross-Site Request Forgery
The GPT3 AI Content Writer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.14. This is due to missing or incorrect nonce validation on the wpaicg_generate_custom_prompt() function. This makes it possible…
*-1.9.14
1.9.15
07/05/2025
AI Power: Complete AI Pack <= 1.8.96 – Authenticated (Admin+) PHP Object Injection via wpaicg_export_ai_forms
The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_ai_forms() function. This allows authenticated…
*-1.8.96
1.8.97
21/01/2025
AI Power: Complete AI Pack <= 1.8.96 – Authenticated (Admin+) PHP Object Injection via wpaicg_export_prompts
The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_prompts function. This allows authenticated…
*-1.8.96
1.8.97
21/01/2025
AI Power: Complete AI Pack <= 1.8.96 – Authenticated (Subscriber+) Server-Side Request Forgery
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.8.96 via the wpaicg_troubleshoot_add_vector(). This makes it possible for authenticated attackers, with subscriber-level access and above,…
*-1.8.96
1.8.97
21/01/2025
AI Power: Complete AI Pack <= 1.8.96 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpaicg_save_image_media function in all versions up to, and including, 1.8.96. This makes it possible for authenticated…
*-1.8.96
1.8.97
21/01/2025
AI Power: Complete AI Pack <= 1.8.89 – Unauthenticated Arbitrary File Upload
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_image_upload' function in all versions up to, and including, 1.8.89. This makes it possible for…
*-1.8.89
1.8.90
30/10/2024
GPT3 AI Content Writer <= 1.8.66 – Authenticated (Contributor+) Stored Cross-Site Scripting
The GPT3 AI Content Writer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.66 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-1.8.66
1.8.67
01/07/2024
GPT3 AI Content Writer <= 1.8.12 – Cross-Site Request Forgery
The GPT3 AI Content Writer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.12. This is due to missing or incorrect nonce validation on the wpaicg_export_logs_callback() function. This makes it possible…
*-1.8.12
1.8.13
27/12/2023
AI Power: Complete AI Pack – Powered by GPT-4 <= 1.8.1 – Missing Authorization to Sensitive Data Exposure
The AI Power: Complete AI Pack – Powered by GPT-4 plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpaicg_export_logs_callback() function in all versions up to, and including, 1.8.2. This makes…
*-1.8.2
1.8.3
27/12/2023
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
1.4.10-1.7.37
1.7.38
18/07/2023
GPT AI Power <= 1.4.37 – Missing Authorization
The GPT AI Power plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an unknown function in versions up to, and including, 1.4.37. This makes it possible for authenticated attackers, with subscriber-level…
*-1.4.37
1.4.38
19/01/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.