AI Power: Complete AI Pack PHP Object Injection Vulnerability

Vulnerability

A PHP Object Injection vulnerability has been identified in the 'AI Power: Complete AI Pack' WordPress plugin, affecting versions through 1.8.96. The vulnerability arises from the deserialization of untrusted data in the '$form['post_content']' variable, within the 'wpaicg_export_ai_forms()' function. This flaw allows authenticated attackers with administrative privileges to inject a PHP object. While the vulnerable plugin does not contain a direct 'Proof of Concept' chain, the presence of such a chain through an additional plugin or theme could enable the attacker to delete arbitrary files, access sensitive information, or execute code.

Impact

Exploitation of this vulnerability could lead to unauthorized PHP object injection, with potential consequences depending on the presence of a 'Proof of Concept' chain through other installed plugins or themes.

Reproduction

To reproduce this vulnerability, an authenticated user with administrative privileges can use the 'wpaicg_export_ai_forms' function to export AI forms. This process involves the deserialization of the 'post_content' variable, which can be manipulated to inject a PHP object.

Remediation

Users are advised to update the 'AI Power: Complete AI Pack' WordPress plugin to version 1.8.97 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.8
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.