CVE-2024-52384 CRITICAL

CVE-2024-52384: WordPress Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation plugin <= 2.4.9 - Arbitrary File Upload vulnerability

Vendor Wpmonks
Product Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation
Weakness CWE-434 · Unrestricted file upload
Published November 14, 2024
Last update April 28, 2026

CVSS base score

9.9/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Unrestricted Upload of File with Dangerous Type vulnerability in wpmonks Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation ai-content-generator allows Upload a Web Shell to a Web Server.This issue affects Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation: from n/a through <= 2.4.9.

Explanation of Vulnerability in Simple Terms

02Summary

Sage AI allows authenticated users to upload files without restriction, potentially enabling them to upload malicious code or files to the site. An attacker with low-level access can exploit this to compromise the entire WordPress installation, including reading sensitive data, modifying content, and disrupting service. The vulnerability affects all versions up to 2.4.9.

What an attacker can do

03Attacker Capabilities

Upload malicious files and execute code on the site with full control over data and functionality.

Potential impact on your site

04Site Impact

Any user account on your site could upload and run malicious code, compromising your entire WordPress installation.

Conditions required to exploit

05Prerequisites

Attacker needs a low-privilege user account (e.g., subscriber or contributor role) on the WordPress site.

Key dates

06Disclosure timeline

November 14, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE