plugin

Aiomatic Automatic Ai Content Writer Vulnerabilities

10 known security issues reported for the Aiomatic Automatic Ai Content Writer WordPress plugin. Most recent disclosed Jun 23, 2025.

2 high 3 medium

Running Aiomatic Automatic Ai Content Writer on your site? Check whether your installed version is affected.

Scan your site free

Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.5.0 - Authenticated (Subscriber+) Arbitrary File Upload

high

The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aiomatic_image_editor_ajax_submit' function in all versions up to, and including, 2.5.0. This makes it possible for au...

CVSS:
7.5
Affected:
up to 2.5.0
Fixed in:
2.5.1
Disclosed:
Jun 23, 2025

CVE-2025-6206 on NVD →

Aiomatic [aiomatic-automatic-ai-content-writer] < 2.3.7

unknown

[en] The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability checks on multiple functions in all versions up to, and including, 2.3.6. This makes it possible for...

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Mar 8, 2025

CVE-2024-13816 on NVD →

Aiomatic [aiomatic-automatic-ai-content-writer] < 2.3.9

unknown

[en] The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aiomatic_generate_featured_image' function in all versions up to, and including, 2.3.8. This makes it possible fo...

Affected:
up to 2.3.9
Fixed in:
2.3.9
Disclosed:
Mar 8, 2025

CVE-2024-13882 on NVD →

Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.8 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Upload

high

The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aiomatic_generate_featured_image' function in all versions up to, and including, 2.3.8. This makes it possible for aut...

CVSS:
8.8
Affected:
up to 2.3.8
Fixed in:
2.3.9
Disclosed:
Mar 7, 2025

CVE-2024-13882 on NVD →

Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.6 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions

medium

The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability checks on multiple functions in all versions up to, and including, 2.3.6. This makes it possible for auth...

CVSS:
5.4
Affected:
up to 2.3.6
Fixed in:
2.3.7
Disclosed:
Mar 7, 2025

CVE-2024-13816 on NVD →

Aiomatic [aiomatic-automatic-ai-content-writer] < 2.0.6

unknown

[en] The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is due to insufficient limitations on the email recipient and the content in the 'aiomatic_send_email' function which are reachable via AJAX. This makes it p...

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Jul 27, 2024

CVE-2024-5969 on NVD →

AIomatic - Automatic AI Content Writer <= 2.0.5 - Unauthenticated Arbitrary Email Sending

medium

The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is due to insufficient limitations on the email recipient and the content in the 'aiomatic_send_email' function which are reachable via AJAX. This makes it possib...

CVSS:
5.8
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Jun 14, 2024

CVE-2024-5969 on NVD →

Aiomatic [aiomatic-automatic-ai-content-writer] < 1.9.4

unknown

[en] Missing Authorization vulnerability in CodeRevolution Aiomatic.This issue affects Aiomatic: from n/a through 1.9.3.

Affected:
up to 1.9.4
Fixed in:
1.9.4
Disclosed:
Jun 9, 2024

CVE-2024-34435 on NVD →

Aiomatic <= 1.9.3 - Missing Authorization

medium

The Aiomatic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.9.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.9.3
Fixed in:
1.9.4
Disclosed:
May 7, 2024

CVE-2024-34435 on NVD →

Aiomatic [aiomatic-automatic-ai-content-writer] < 2.5.1

unknown
Affected:
up to 2.5.1
Fixed in:
2.5.1

CVE-2025-6206 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database