The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in a function hooked to init, allowing unauthenticated users to update some settings, leading to Stored XSS due to the lack of escaping when outputting them in the admin dashboard
References
Configurations
History
12 May 2025, 15:09
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:quantumcloud:wpbot:*:*:*:*:*:wordpress:*:* | |
First Time |
Quantumcloud wpbot
|
05 May 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/1a5cbcfc-fa55-433a-a76b-3881b6c4bea2 - Exploit |
07 Nov 2023, 04:04
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-352 |
11 May 2023, 18:50
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
First Time |
Quantumcloud ai Chatbot
Quantumcloud |
|
CPE | cpe:2.3:a:quantumcloud:ai_chatbot:*:*:*:*:*:wordpress:*:* | |
References | (MISC) https://wpscan.com/vulnerability/1a5cbcfc-fa55-433a-a76b-3881b6c4bea2 - Exploit |
08 May 2023, 14:17
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-05-08 14:15
Updated : 2025-05-12 15:09
NVD link : CVE-2023-1660
Mitre link : CVE-2023-1660
JSON object : View
Products Affected
quantumcloud
- wpbot
CWE
No CWE.