CVE-2024-12605 Information

Description

The AI Scribe – SEO AI Writer Content Generator Humanizer Blog Writer SEO Optimizer DALLE-3 AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 2.3. This is due to missing or incorrect nonce validation on the l_scribe_content_data\ actions. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Reference

https://plugins.trac.wordpress.org/browser/ai-scribe-the-chatgpt-powered-seo-content-creation-wizard/trunk/article_builder.php#L713 https://www.wordfence.com/threat-intel/vulnerabilities/id/52a8718f-2c4d-4da1-a81f-e93dff3fa43b?source=cve

Share on: