Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter
medium
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 1.8.99
- Fixed in:
- 2.3.17
- Disclosed:
- Apr 30, 2026
CVE-2024-13362 on NVD →
GPT3 AI Content Writer <= 1.9.14 - Cross-Site Request Forgery
medium
The GPT3 AI Content Writer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.14. This is due to missing or incorrect nonce validation on the wpaicg_generate_custom_prompt() function. This makes it possible for unauthenticated attackers to generate prompts via a forge...
- CVSS:
- 4.3
- Affected:
- up to 1.9.14
- Fixed in:
- 1.9.15
- Disclosed:
- May 7, 2025
CVE-2025-47470 on NVD →
AIP: Complete AI Pack (formerly AI Power) [gpt3-ai-content-generator] < 1.9.15
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in senols GPT3 AI Content Writer allows Cross Site Request Forgery. This issue affects GPT3 AI Content Writer: from n/a through 1.9.14.
- Affected:
- up to 1.9.15
- Fixed in:
- 1.9.15
- Disclosed:
- May 7, 2025
CVE-2025-47470 on NVD →
AIP: Complete AI Pack (formerly AI Power) [gpt3-ai-content-generator] < 1.8.97
unknown
[en] The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.8.96 via the wpaicg_troubleshoot_add_vector(). This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locat...
- Affected:
- up to 1.8.97
- Fixed in:
- 1.8.97
- Disclosed:
- Jan 22, 2025
CVE-2024-13360 on NVD →
AIP: Complete AI Pack (formerly AI Power) [gpt3-ai-content-generator] < 1.8.97
unknown
[en] The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpaicg_save_image_media function in all versions up to, and including, 1.8.96. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload imag...
- Affected:
- up to 1.8.97
- Fixed in:
- 1.8.97
- Disclosed:
- Jan 22, 2025
CVE-2024-13361 on NVD →
AI Power: Complete AI Pack <= 1.8.96 - Authenticated (Admin+) PHP Object Injection via wpaicg_export_prompts
high
The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_prompts function. This allows authenticated attackers, with administrative privile...
- CVSS:
- 7.2
- Affected:
- up to 1.8.96
- Fixed in:
- 1.8.97
- Disclosed:
- Jan 21, 2025
CVE-2025-0428 on NVD →
AI Power: Complete AI Pack <= 1.8.96 - Authenticated (Admin+) PHP Object Injection via wpaicg_export_ai_forms
high
The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_ai_forms() function. This allows authenticated attackers, with administrative priv...
- CVSS:
- 7.2
- Affected:
- up to 1.8.96
- Fixed in:
- 1.8.97
- Disclosed:
- Jan 21, 2025
CVE-2025-0429 on NVD →
AI Power: Complete AI Pack <= 1.8.96 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution
medium
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpaicg_save_image_media function in all versions up to, and including, 1.8.96. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload image fil...
- CVSS:
- 6.3
- Affected:
- up to 1.8.96
- Fixed in:
- 1.8.97
- Disclosed:
- Jan 21, 2025
CVE-2024-13361 on NVD →
AI Power: Complete AI Pack <= 1.8.96 - Authenticated (Subscriber+) Server-Side Request Forgery
medium
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.8.96 via the wpaicg_troubleshoot_add_vector(). This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations...
- CVSS:
- 5.4
- Affected:
- up to 1.8.96
- Fixed in:
- 1.8.97
- Disclosed:
- Jan 21, 2025
CVE-2024-13360 on NVD →
AIP: Complete AI Pack (formerly AI Power) [gpt3-ai-content-generator] < 1.8.90
unknown
[en] The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_image_upload' function in all versions up to, and including, 1.8.89. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's s...
- Affected:
- up to 1.8.90
- Fixed in:
- 1.8.90
- Disclosed:
- Oct 31, 2024
CVE-2024-10392 on NVD →
AI Power: Complete AI Pack <= 1.8.89 - Unauthenticated Arbitrary File Upload
critical
The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_image_upload' function in all versions up to, and including, 1.8.89. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server...
- CVSS:
- 9.8
- Affected:
- up to 1.8.89
- Fixed in:
- 1.8.90
- Disclosed:
- Oct 30, 2024
CVE-2024-10392 on NVD →
AIP: Complete AI Pack (formerly AI Power) [gpt3-ai-content-generator] < 1.8.67
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Senol Sahin GPT3 AI Content Writer allows Stored XSS.This issue affects GPT3 AI Content Writer: from n/a through 1.8.66.
- Affected:
- up to 1.8.67
- Fixed in:
- 1.8.67
- Disclosed:
- Jul 21, 2024
CVE-2024-37465 on NVD →
GPT3 AI Content Writer <= 1.8.66 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The GPT3 AI Content Writer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.66 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts i...
- CVSS:
- 6.4
- Affected:
- up to 1.8.66
- Fixed in:
- 1.8.67
- Disclosed:
- Jul 1, 2024
CVE-2024-37465 on NVD →
AIP: Complete AI Pack (formerly AI Power) [gpt3-ai-content-generator] < 1.8.13
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Senol Sahin AI Power: Complete AI Pack – Powered by GPT-4.This issue affects AI Power: Complete AI Pack – Powered by GPT-4: from n/a through 1.8.12.
- Affected:
- up to 1.8.13
- Fixed in:
- 1.8.13
- Disclosed:
- Feb 29, 2024
CVE-2023-51528 on NVD →
AIP: Complete AI Pack (formerly AI Power) [gpt3-ai-content-generator] < 1.8.3
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Senol Sahin AI Power: Complete AI Pack – Powered by GPT-4.This issue affects AI Power: Complete AI Pack – Powered by GPT-4: from n/a through 1.8.2.
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.3
- Disclosed:
- Dec 29, 2023
CVE-2023-51527 on NVD →
AI Power: Complete AI Pack – Powered by GPT-4 <= 1.8.1 - Missing Authorization to Sensitive Data Exposure
medium
The AI Power: Complete AI Pack – Powered by GPT-4 plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpaicg_export_logs_callback() function in all versions up to, and including, 1.8.2. This makes it possible for unauthenticated attackers to export the plugin's logs which...
- CVSS:
- 5.3
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.3
- Disclosed:
- Dec 27, 2023
CVE-2023-51527 on NVD →
GPT3 AI Content Writer <= 1.8.12 - Cross-Site Request Forgery
medium
The GPT3 AI Content Writer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.12. This is due to missing or incorrect nonce validation on the wpaicg_export_logs_callback() function. This makes it possible for unauthenticated attackers to trigger a log export via a for...
- CVSS:
- 4.3
- Affected:
- up to 1.8.12
- Fixed in:
- 1.8.13
- Disclosed:
- Dec 27, 2023
CVE-2023-51528 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- 1.4.10 – 1.7.37
- Fixed in:
- 1.7.38
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
AIP: Complete AI Pack (formerly AI Power) [gpt3-ai-content-generator] < 1.4.38
unknown
[en] The GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training WordPress plugin before 1.4.38 does not perform any kind of nonce or privilege checks before letting logged-in users modify arbitrary posts.
- Affected:
- up to 1.4.38
- Fixed in:
- 1.4.38
- Disclosed:
- Feb 13, 2023
CVE-2023-0405 on NVD →
GPT AI Power <= 1.4.37 - Missing Authorization
high
The GPT AI Power plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an unknown function in versions up to, and including, 1.4.37. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update arbitrary posts.
- CVSS:
- 8.1
- Affected:
- up to 1.4.37
- Fixed in:
- 1.4.38
- Disclosed:
- Jan 19, 2023
CVE-2023-0405 on NVD →
AIP: Complete AI Pack (formerly AI Power) [gpt3-ai-content-generator] < 1.7.40
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.7.40
- Fixed in:
- 1.7.40
CVE-2023-33999 on NVD →
AIP: Complete AI Pack (formerly AI Power) [gpt3-ai-content-generator] < 1.8.97
unknown
- Affected:
- up to 1.8.97
- Fixed in:
- 1.8.97
CVE-2025-0428 on NVD →
AIP: Complete AI Pack (formerly AI Power) [gpt3-ai-content-generator] < 1.8.97
unknown
- Affected:
- up to 1.8.97
- Fixed in:
- 1.8.97
CVE-2025-0429 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database