Home » Database

AVID-2026-R1453

Description

WordPress AI Engine plugin <= 2.1.4 - Arbitrary File Upload vulnerability (CVE-2024-29100)

Details

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.

Reason for inclusion in AVID: CVE-2024-29100 is an Unrestricted Upload of File with Dangerous Type vulnerability (arbitrary file upload) in the WordPress AI Engine: ChatGPT Chatbot plugin (<= 2.1.4). This is a software vulnerability in a component used to deliver AI capabilities, i.e., an AI software stack dependency/plugin. It affects the AI deployment stack and could enable compromise of an AI-enabled web application, satisfying a security vulnerability in a software supply chain for general-purpose AI systems. The report provides CVSS/CWE signals and references, giving sufficient signal.

References

Affected or Relevant Artifacts

  • Developer: OpenAI
  • Deployer: OpenAI
  • Artifact Details:
TypeName
SystemAI Engine: ChatGPT Chatbot

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Base Score9.1
Base Severity🔴 Critical
Attack VectorNETWORK
Attack Complexity🟢 Low
Privileges Required🔴 High
User InteractionNONE
ScopeCHANGED
Confidentiality Impact🔴 High
Integrity Impact🔴 High
Availability Impact🔴 High

CWE

IDDescription
CWE-434CWE-434 Unrestricted Upload of File with Dangerous Type

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2024-03-28
  • Version: 0.3.3
  • AVID Entry