The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability checks on multiple functions in all versions up to, and including, 2.3.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update and delete posts, list and delete batches, list assistant uploaded files, delete personas, delete forms, delete templates, and clear logs. The vulnerability was partially patched in version 2.3.5.
History

Mon, 24 Mar 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Coderevolution
Coderevolution aiomatic
CPEs cpe:2.3:a:coderevolution:aiomatic:*:*:*:*:*:wordpress:*:*
Vendors & Products Coderevolution
Coderevolution aiomatic

Mon, 10 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 08 Mar 2025 08:30:00 +0000

Type Values Removed Values Added
Description The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability checks on multiple functions in all versions up to, and including, 2.3.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update and delete posts, list and delete batches, list assistant uploaded files, delete personas, delete forms, delete templates, and clear logs. The vulnerability was partially patched in version 2.3.5.
Title Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.6 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-03-10T15:56:48.009Z

Reserved: 2025-01-30T23:49:33.047Z

Link: CVE-2024-13816

cve-icon Vulnrichment

Updated: 2025-03-10T15:56:42.845Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-08T09:15:31.077

Modified: 2025-03-24T14:23:45.580

Link: CVE-2024-13816

cve-icon Redhat

No data.