Extension WordPress

Vulnérabilités WPBot – AI ChatBot for Live Support, Lead Generation, AI Services, page 2

Cette page rassemble les failles publiées pour WPBot – AI ChatBot for Live Support, Lead Generation, AI Services, leurs plages de versions affectées et les correctifs signalés dans la base locale.

40Vulnérabilités
5Critiques
40Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

40 fiches

CVE-2023-5254 Moyenne · 5,3
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.8.9 – Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_user

The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9 via the qcld_wb_chatbot_check_user function. This can allow unauthenticated attackers to extract sensitive data including confirmation as to whether a user…

Versions affectées

*-4.8.9

Correctif

4.9.1

Publication

11/10/2023

CVE-2023-5533 Moyenne · 5,3
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.8.9 and 4.9.2 – Missing Authorization on AJAX actions

The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks on the corresponding functions in versions up to, and including, 4.8.9 as well as 4.9.2. This makes it possible…

Versions affectées

*-4.8.9, 4.9.2

Correctif

4.9.1, 4.9.3

Publication

11/10/2023

CVE-2023-5534 Moyenne · 4,3
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.8.9 and 4.9.2 – Cross-Site Request Forgery on AJAX actions

The AI ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.9 and 4.9.2. This is due to missing or incorrect nonce validation on the corresponding functions. This makes it possible…

Versions affectées

*-4.8.9, 4.9.2

Correctif

4.9.1, 4.9.3

Publication

11/10/2023

CVE-2023-5212 Critique · 9,6
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.8.9 and 4.9.2- Authenticated (Subscriber+) Arbitrary File Deletion via qcld_openai_delete_training_file

The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as well as version 4.9.2. This makes it possible for authenticated attackers with subscriber privileges to delete arbitrary files…

Versions affectées

*-4.8.9, 4.9.2

Correctif

4.9.1, 4.9.3

Publication

11/10/2023

CVE-2023-5204 Critique · 9,8
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.8.9 – Unauthenticated SQL Injection via qc_wpbo_search_response

The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

Versions affectées

*-4.8.9

Correctif

4.9.1

Publication

11/10/2023

CVE-2023-5241 Critique · 9,6
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.8.9 and 4.9.2 – Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_file

The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to append "

Versions affectées

*-4.8.9, 4.9.2

Correctif

4.9.1, 4.9.3

Publication

11/10/2023

CVE-2023-44993 Moyenne · 5,3
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot <= 4.7.8 – Cross-Site Request Forgery via qc_wp_latest_update_check

The ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.7.8. This is due to missing or incorrect nonce validation on the qc_wp_latest_update_check function. This makes it possible for unauthenticated attackers…

Versions affectées

*-4.7.8

Correctif

4.7.9

Publication

03/10/2023

CVE-2023-4253 Moyenne · 4,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot <= 4.7.7 – Authenticated (Administrator+) Stored Cross-Site Scripting in FAQ Builder

The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions up to, and including, 4.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…

Versions affectées

*-4.7.7

Correctif

4.7.8

Publication

08/08/2023

CVE-2023-4254 Moyenne · 4,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot 4.7.7 – Authenticated (Administrator+) Stored Cross-Site Scripting in Language Settings

The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via Language Settings in versions up to, and including, 4.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions…

Versions affectées

*-4.7.7

Correctif

4.7.8

Publication

08/08/2023

CVE-2023-2811 Moyenne · 4,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.5.5 – Authenticated (Administrator+) Stored Cross-Site Scripting

The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-4.5.5

Correctif

4.5.6

Publication

25/05/2023

CVE-2023-2742 Moyenne · 4,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.5.4 – Authenticated (Administrator+) Stored Cross-Site Scripting

The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-4.5.4

Correctif

4.5.5

Publication

22/05/2023

CVE-2023-3175 Moyenne · 4,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.6.0 – Authenticated (Administrator+) Stored Cross-Site Scripting

The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings on the 'language' tab in versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-4.6.0

Correctif

4.6.1

Publication

22/05/2023

CVE-2023-1011 Moyenne · 6,1
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot <= 4.4.4 – Unauthenticated Stored Cross-Site Scripting via Cross-Site Request Forgery

The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 4.4.4 due to insufficient input sanitization and output escaping and a lack of nonce check on the…

Versions affectées

*-4.4.4

Correctif

4.4.5

Publication

20/04/2023

CVE-2023-1651 Moyenne · 6,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot <= 4.4.8 – Authenticated (Subscriber+) Stored Cross-Site Scripting via openai_settings_option_callback

The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘openai_settings_option_callback’ function in versions up to, and including, 4.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-4.4.8

Correctif

4.4.9

Publication

12/04/2023

CVE-2023-1649 Moyenne · 4,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.4.9 – Authenticated (Administrator+) Stored Cross-Site Scripting

The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-4.4.9

Correctif

4.5.1

Publication

12/04/2023

CVE-2023-1660 Moyenne · 6,5
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot <= 4.4.8 – Unauthenticated Stored Cross-Site Scripting in Admin Dashboard

The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting in the Admin Dashboard in versions up to, and including, 4.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers (leveraging…

Versions affectées

*-4.4.8

Correctif

4.4.9

Publication

12/04/2023

CVE-2023-1650 Critique · 9,8
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot <= 4.4.6 – Unauthenticated PHP Object Injection via Cookies

The ChatBot plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.4.6 via deserialization of untrusted input from cookies This allows unauthenticated attackers to inject a PHP Object. No POP chain is…

Versions affectées

*-4.4.6

Correctif

4.4.7

Publication

12/04/2023

Vulnérabilité Moyenne · 5,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.4.7 – Missing Authorization on openai_settings_option_callback

The AI ChatBot plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the openai_settings_option_callback function in versions up to, and including, 4.4.7. This makes it possible for subscriber-level attackers to change…

Versions affectées

*-4.4.7

Correctif

4.4.8

Publication

29/03/2023

CVE-2022-47613 Moyenne · 4,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot <= 4.3.0 – Authenticated (Admin+) Cross-Site Scripting

The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘qlcd_wp_chatbot_email_sub’ parameter in versions up to, and including, 4.3.0 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to…

Versions affectées

*-4.3.0

Correctif

4.3.1

Publication

27/01/2023

CVE-2023-24415 Moyenne · 5,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot <= 4.2.8 – Cross-Site Request Forgery to Stored Cross-Site Scripting and Settings Reset

The ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.8. This is due to missing or incorrect nonce validation on the 'qcld_wb_chatbot_save_options' function. This makes it possible for unauthenticated attackers…

Versions affectées

*-4.2.8

Correctif

4.2.9

Publication

27/01/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités