7.2
CVE-2024-6451
- EPSS 0.82%
- Veröffentlicht 19.08.2024 06:15:05
- Zuletzt bearbeitet 27.05.2025 21:05:27
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
AI Engine < 2.5.1 - Admin+ RCE
AI Engine <= 2.5.0 - Authenticated (Admin+) Remote Code Execution
AI Engine < 2.4.3 is susceptible to remote-code-execution (RCE) via Log Poisoning. The AI Engine WordPress plugin before 2.5.1 fails to validate the file extension of "logs_path", allowing Administrators to change log filetypes from .log to .php.
Mögliche Gegenmaßnahme
AI Engine – The Chatbot, AI Framework & MCP for WordPress: Update to version 2.5.1, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
AI Engine – The Chatbot, AI Framework & MCP for WordPress
Version
*-2.5.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.82% | 0.523 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.
https://wpscan.com/vulnerability/fc06d413-a227-470c-a5b7-cdab57aeab34/
https://www.wordfence.com/threat-intel/vulnerabilities/id/d9f6b761-9c4b-4dcc-885d-9a5b4e8e534d