CVE-2025-0429 Details
Description
The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the $form['post_content'] variable through the wpaicg_export_ai_forms() function. This allows authenticated attackers, with administrative privileges, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
A PHP Object Injection vulnerability has been identified in the 'AI Power: Complete AI Pack' WordPress plugin, affecting versions through 1.8.96. The vulnerability arises from the deserialization of untrusted data in the '$form['post_content']' variable, within the 'wpaicg_export_ai_forms()' function. This flaw allows authenticated attackers with administrative privileges to inject a PHP object. While the vulnerable plugin does not contain a direct 'Proof of Concept' chain, the presence of such a chain through an additional plugin or theme could enable the attacker to delete arbitrary files, access sensitive information, or execute code.
Users are advised to update the 'AI Power: Complete AI Pack' WordPress plugin to version 1.8.97 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| aipower aipower | < 1.8.97 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 24, 2025 | Initial Analysis | [email protected] |
| Jan 22, 2025 | New CVE Received | [email protected] |