Aipower's vulnerability profile centers on a single web application product and reflects the security demands of a cloud-connected software service. The recurring weakness classes—including deserialization flaws, cross-site request forgery, cross-site scripting, and information exposure—are characteristic of web application architectures and input-handling complexity. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aipower over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-13361HIGH The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpaicg_save_image_media function in all versions u | Jan 22, 2025 | 8.8 | 24 | NO | NO |
CVE-2023-51528HIGH Cross-Site Request Forgery (CSRF) vulnerability in Senol Sahin AI Power: Complete AI Pack – Powered by GPT-4.This issue affects AI Power: Complete AI Pack – Powered by GPT-4: from | Feb 29, 2024 | 8.8 | 23 | NO | NO |
CVE-2025-0429HIGH The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the | Jan 22, 2025 | 7.2 | 22 | NO | NO |
CVE-2025-0428HIGH The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.96 via deserialization of untrusted input from the | Jan 22, 2025 | 7.2 | 22 | NO | NO |
CVE-2023-51527HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Senol Sahin AI Power: Complete AI Pack – Powered by GPT-4.This issue affects AI Power: Complete AI Pack | Dec 29, 2023 | 7.5 | 22 | NO | NO |
CVE-2024-37465MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Senol Sahin GPT3 AI Content Writer allows Stored XSS.This issue affects | Jul 21, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-13360MEDIUM The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.8.96 via the wpaicg_troubleshoot_add_vector | Jan 22, 2025 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aipower.
Media articles that mention a CVE ID that affects a product developed by Aipower — matched by CVE ID, not by vendor name.