CVE-2024-12471: Postsaint Post Saint: Chatgpt, GPT4, Dall-E, Stable Diffusion, Pexels, Dezgo Ai Text & Image Generator

High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.

The Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator plugin for WordPress is vulnerable to arbitrary files uploads due to a missing capability check and file type validation on the add_image_to_library AJAX action function in all versions up to, and including, 1.3.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files that make remote code execution possible.

Affected products

  • Postsaint Post Saint: Chatgpt, GPT4, Dall-E, Stable Diffusion, Pexels, Dezgo Ai Text & Image Generator: up to and including 1.3.1

Published 2025-01-07. Last modified 2026-06-17.