What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in wpmonks Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation ai-content-generator allows Upload a Web Shell to a Web Server.This issue affects Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation: from n/a through <= 2.4.9.
Explanation of Vulnerability in Simple Terms
02Summary
Sage AI allows authenticated users to upload files without restriction, potentially enabling them to upload malicious code or files to the site. An attacker with low-level access can exploit this to compromise the entire WordPress installation, including reading sensitive data, modifying content, and disrupting service. The vulnerability affects all versions up to 2.4.9.
What an attacker can do
03Attacker Capabilities
Upload malicious files and execute code on the site with full control over data and functionality.
Potential impact on your site
04Site Impact
Any user account on your site could upload and run malicious code, compromising your entire WordPress installation.
Conditions required to exploit
05Prerequisites
Attacker needs a low-privilege user account (e.g., subscriber or contributor role) on the WordPress site.
Key dates
06Disclosure timeline
November 14, 2024
CVE published
April 28, 2026
Record updated