What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.2.63.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.2.63.
Explanation of Vulnerability in Simple Terms
The AI Engine: ChatGPT Chatbot plugin allows authenticated administrators to upload files without proper validation. An attacker with admin access can upload malicious files to compromise the site. The vulnerability affects versions up to 2.2.63. Update to a version newer than 2.2.63 to remediate.
What an attacker can do
Upload malicious files to the site and execute code if they have admin access.
Potential impact on your site
A compromised admin account can upload files leading to full site takeover and data breach.
Conditions required to exploit
Attacker must have administrator-level privileges on the WordPress site.
Key dates
External resources
Related vulnerabilities