Description
WordPress Plugin 10Web AI Assistant-AI content writing assistant is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently install and activate any plugin from the WordPress repo. WordPress Plugin 10Web AI Assistant-AI content writing assistant version 1.0.18 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.19 or latest
References
Related Vulnerabilities
MySQL CVE-2018-2586 Vulnerability (CVE-2018-2586)
Apache HTTP Server CVE-2024-40725 Vulnerability (CVE-2024-40725)
WordPress Plugin WP Activity Log PHP Object Injection (3.2.5)
Oracle Database Server CVE-2013-1538 Vulnerability (CVE-2013-1538)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Cross-Site Scripting (3.9.7)