s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2024-49671

📛 CVE Title

WordPress AI Postpix plugin <= 1.1.8 - Arbitrary File Upload vulnerability

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Dogu Pekgoz AI Image Generator for Your Content & Featured Images – AI Postpix ai-postpix allows Upload a Web Shell to a Web Server.This issue affects AI Image Generator for Your Content & Featured Images – AI Postpix: from n/a through <= 1.1.8.

Overview

State
PUBLISHED
Assigner (CNA)
Patchstack
CVSS severity
CRITICAL
CVSS score
CVSS 9.9 / 10 9.9 9.9 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Effective score
9.9 / 10 CRITICAL source: CNA overview
CWE(s)
CWE-434
Reserved
2024-10-17
Published
2024-10-23 17:34 UTC
Last updated
2026-04-29 11:51 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/49xxx/CVE-2024-49671.json
Linked Threat
CVE-2024-49671 — AI Image Generator for Your Content & Featured Images – AI Postpix <= 1.1.8 - Authenticated (Subscriber+) Arbitrary File Upload

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2024-43529
Assigner
Patchstack
Published
Oct 23, 2024, 3:34:23 PM
Updated
Apr 29, 2026, 9:51:53 AM
EUVD base score (CVSS 3.1)
9.9 / 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EUVD-reported EPSS
0.4900
Vendors
Dogu Pekgoz
Products
AI Image Generator for Your Content & Featured Images – AI Postpix (n/a ≤1.1.8)
AI Image Generator for Your Content & Featured Images – AI Postpix (0 ≤1.1.8)
Aliases
GHSA-4qjx-wpr6-v7fg

ENISA description: Unrestricted Upload of File with Dangerous Type vulnerability in Dogu Pekgoz AI Image Generator for Your Content & Featured Images – AI Postpix ai-postpix allows Upload a Web Shell to a Web Server.This issue affects AI Image Generator for Your Content & Featured Images – AI Postpix: from n/a through <= 1.1.8.

EUVD references (1)

Affected products (1)

VendorProductVersionsPlatforms
Dogu Pekgoz AI Image Generator for Your Content & Featured Images – AI Postpix 0 (affected)

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

Web references (5)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

Indicators (2)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
domain server.this no local data 2026-05-18 21:19 UTC
cve CVE-2024-49671 no local data 2026-06-06 14:17 UTC

Flagged vendors

    Remediations (22)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • web:www.bleepingcomputer.com

      Microsoft has released an out-of-band (OOB) update to fix a security vulnerabilities affecting Windows 11 Enterprise devices that receive hotpatch updates instead of the regular Patch Tuesday ...

      2026-08-04 10:46 UTC
    • web:blog.qualys.com

      EVALUATE Vendor-Suggested Mitigation with Policy Audit With Qualys Policy Audit's Out-of-the-Box Mitigation or Compensatory Controls, reduce the risk of a vulnerability being exploited because the remediation ( fix / patch ) cannot be done now; these security controls are not recommended by any industry standards, such as CIS, DISA-STIG.

      2026-08-04 10:46 UTC
    • web:cybernews.com

      Microsoft's July 2026 Patch Tuesday fixes a record 622 vulnerabilities and begins mandatory Kerberos RC4 enforcement, marking one of Windows' biggest security updates.

      2026-08-04 10:46 UTC
    • web:www.nist.gov

      NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation's cybersecurity infrastructure.

      2026-08-04 10:46 UTC
    • web:learn.microsoft.com

      Windows 11, version 25H2 is now available for all eligible devices. Devices running Home and Pro editions of Windows 11 that are not managed by IT departments will receive the update to Windows 11, version 25H2 through the machine learning-based intelligent rollout.

      2026-08-04 10:46 UTC
    • web:www.cisecurity.org

      We recommend the following actions be taken: Apply appropriate patches or appropriate mitigations provided by Microsoft to vulnerable systems immediately after appropriate testing. (M1051: Update Software) Safeguard 7.1: Establish and Maintain a Vulnerability Management Process: Establish and maintain a documented vulnerability management process for enterprise assets. Review and update ...

      2026-08-04 10:46 UTC
    • Wordfence remediation: AI Image Generator for Your Content & Featured Images – AI Postpix
      Wordfence

      Update to version 1.1.8.1, or a newer patched version

      2026-06-06 14:17 UTC
    • web:www.bitdefender.com

      The GravityZone Patch Management module includes several features, such as on-demand or scheduled patch scanning, automatic or manual patching, and reporting on missing patches. Learn more about Bitdefender Patch Management supported vendors and products.

      2026-05-22 10:33 UTC
    • web:www.notebookcheck.net

      Microsoft's February 2026 Windows 11 updates (KB5077181 and KB5075941) add security patches, bug fixes, and new Secure Boot rollout signals ahead of certificate expirations starting in June 2026.

      2026-05-22 10:33 UTC
    • web:www.maketecheasier.com

      Check out the latest Windows 11 and Windows 10 update problems and their solutions, as recommended by Microsoft experts.

      2026-05-22 10:33 UTC
    • web:www.neowin.net

      Microsoft has released Patch Tuesday updates for Windows 11 KB5077181, KB5075941 for February 2026. Here's what's included.

      2026-05-22 10:33 UTC
    • web:nvd.nist.gov

      An official website of the United States government Here's how you know

      2026-05-22 10:33 UTC
    • web:www.ninjaone.com

      Catalog of Microsoft KB updates with insights on performance & user sentiment. Find out what's working, what's not, & make informed decisions.

      2026-05-22 03:32 UTC
    • web:cybersecuritynews.com

      Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.

      2026-05-22 03:32 UTC
    • web:www.sentinelone.com

      CVE - 2024 -20671 is an authentication bypass vulnerability in Windows Defender Antimalware Platform. Learn about its impact, affected versions, and mitigation .

      2026-05-22 03:32 UTC
    • web:www.tomshardware.com

      Microsoft released security update KB5034441 on Patch Tuesday to fix a BitLocker encryption bypass vulnerability affecting Windows 10 users. However, some users are experiencing an update failure ...

      2026-05-22 03:32 UTC
    • web:pureinfotech.com

      Fix Windows 11 stuck in BitLocker recovery screen To fix the issue with the BitLocker recovery screen on Windows 11, you would need another computer ( or a mobile phone) with internet access, and then follow these steps: Open your Microsoft account online. Confirm the computer's name from the list to find the recovery key.

      2026-05-22 03:32 UTC
    • web:blog.qualys.com

      Microsoft's February 2026 Patch Tuesday focuses on closing security gaps that attackers could exploit, reinforcing the importance of timely patching in enterprise environments. Here's a quick…

      2026-05-22 03:32 UTC
    • web:www.bleepingcomputer.com

      Microsoft has released emergency SharePoint security updates for two zero-day vulnerabilities tracked as CVE -2025-53770 and CVE -2025-53771 that have compromised services worldwide in "ToolShell ...

      2026-05-22 03:32 UTC
    • web:portal.msrc.microsoft.com

      The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

      2026-05-22 03:32 UTC
    • web:www.cisa.gov

      . For more information see MAR-251132.c1.v1 Exploitation of SharePoint Vulnerabilities and CISA Releases Malware Analysis Report Associated with Microsoft SharePoint Vulnerabilities. Update (07/31/2025): CISA has updated this alert to provide clarification on antivirus and endpoint detection and response (EDR) solutions, and details regarding mitigations related to the IIS server. Update (07 ...

      2026-05-22 03:32 UTC
    • web:www.computerworld.com

      Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...

      2026-05-22 03:32 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2024-49671.json.

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:postpix:ai_postpix:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "ai_postpix",
                "vendor": "postpix",
                "versions": [
                  {
                    "lessThanOrEqual": "1.1.8",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-49671",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-23T17:21:58.541402Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-23T17:27:17.402Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "packageName": "ai-postpix",
              "product": "AI Image Generator for Your Content & Featured Images \u2013 AI Postpix",
              "vendor": "Dogu Pekgoz",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "1.1.8.1",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "1.1.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "theviper17 | Patchstack Bug Bounty Program"
            }
          ],
          "datePublic": "2026-04-22T14:36:43.239Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Unrestricted Upload of File with Dangerous Type vulnerability in Dogu Pekgoz AI Image Generator for Your Content & Featured Images \u2013 AI Postpix ai-postpix allows Upload a Web Shell to a Web Server.<p>This issue affects AI Image Generator for Your Content & Featured Images \u2013 AI Postpix: from n/a through <= 1.1.8.</p>"
                }
              ],
              "value": "Unrestricted Upload of File with Dangerous Type vulnerability in Dogu Pekgoz AI Image Generator for Your Content & Featured Images \u2013 AI Postpix ai-postpix allows Upload a Web Shell to a Web Server.This issue affects AI Image Generator for Your Content & Featured Images \u2013 AI Postpix: from n/a through <= 1.1.8."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-650",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Upload a Web Shell to a Web Server"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-434",
                  "description": "Unrestricted Upload of File with Dangerous Type",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-29T09:51:53.607Z",
            "orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
            "shortName": "Patchstack"
          },
          "references": [
            {
              "tags": [
                "vdb-entry"
              ],
              "url": "https://patchstack.com/database/Wordpress/Plugin/ai-postpix/vulnerability/wordpress-ai-postpix-plugin-1-1-8-arbitrary-file-upload-vulnerability?_s_id=cve"
            }
          ],
          "title": "WordPress AI Postpix plugin <= 1.1.8 - Arbitrary File Upload vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
        "assignerShortName": "Patchstack",
        "cveId": "CVE-2024-49671",
        "datePublished": "2024-10-23T15:34:23.381Z",
        "dateReserved": "2024-10-17T09:52:02.527Z",
        "dateUpdated": "2026-04-29T09:51:53.607Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }