Copymatic – AI Content Writer & Generator <= 2.1 - Cross-Site Request Forgery to Settings Update
medium
The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the 'copymatic-menu' page. This makes it possible for unauthenticated attackers to update the copymatic_apikey...
- CVSS:
- 4.3
- Affected:
- up to 2.1
- Fix:
- No patched version reported
- Disclosed:
- Jul 17, 2025
CVE-2025-6781 on NVD →
Copymatic – AI Content Writer & Generator <= 1.9 - Missing Authorization
medium
The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the copymatic_import_article() function in versions up to, and including, 1.9. This makes it possible for authenticated attackers, with subscriber-level access and a...
- CVSS:
- 4.3
- Affected:
- up to 1.9
- Fixed in:
- 2.0
- Disclosed:
- Jun 6, 2024
CVE-2024-35716 on NVD →
Copymatic – AI Content Writer & Generator <= 1.6 - Unauthenticated Arbitrary File Upload
critical
The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
- CVSS:
- 9.8
- Affected:
- up to 1.6
- Fixed in:
- 1.7
- Disclosed:
- May 14, 2024
CVE-2024-31351 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database