Extension WordPress
Vulnérabilités WPBot – AI ChatBot for Live Support, Lead Generation, AI Services, page 2
Cette page rassemble les failles publiées pour WPBot – AI ChatBot for Live Support, Lead Generation, AI Services, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WPBot – AI ChatBot for Live Support, Lead Generation, AI Services
40 fiches
AI ChatBot <= 4.8.9 – Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_user
The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9 via the qcld_wb_chatbot_check_user function. This can allow unauthenticated attackers to extract sensitive data including confirmation as to whether a user…
*-4.8.9
4.9.1
11/10/2023
AI ChatBot <= 4.8.9 and 4.9.2 – Missing Authorization on AJAX actions
The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks on the corresponding functions in versions up to, and including, 4.8.9 as well as 4.9.2. This makes it possible…
*-4.8.9, 4.9.2
4.9.1, 4.9.3
11/10/2023
AI ChatBot <= 4.8.9 and 4.9.2 – Cross-Site Request Forgery on AJAX actions
The AI ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.9 and 4.9.2. This is due to missing or incorrect nonce validation on the corresponding functions. This makes it possible…
*-4.8.9, 4.9.2
4.9.1, 4.9.3
11/10/2023
AI ChatBot <= 4.8.9 and 4.9.2- Authenticated (Subscriber+) Arbitrary File Deletion via qcld_openai_delete_training_file
The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as well as version 4.9.2. This makes it possible for authenticated attackers with subscriber privileges to delete arbitrary files…
*-4.8.9, 4.9.2
4.9.1, 4.9.3
11/10/2023
AI ChatBot <= 4.8.9 – Unauthenticated SQL Injection via qc_wpbo_search_response
The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
*-4.8.9
4.9.1
11/10/2023
AI ChatBot <= 4.8.9 and 4.9.2 – Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_file
The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to append "
*-4.8.9, 4.9.2
4.9.1, 4.9.3
11/10/2023
ChatBot <= 4.7.8 – Cross-Site Request Forgery via qc_wp_latest_update_check
The ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.7.8. This is due to missing or incorrect nonce validation on the qc_wp_latest_update_check function. This makes it possible for unauthenticated attackers…
*-4.7.8
4.7.9
03/10/2023
ChatBot <= 4.7.7 – Authenticated (Administrator+) Stored Cross-Site Scripting in FAQ Builder
The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions up to, and including, 4.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
*-4.7.7
4.7.8
08/08/2023
ChatBot 4.7.7 – Authenticated (Administrator+) Stored Cross-Site Scripting in Language Settings
The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via Language Settings in versions up to, and including, 4.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions…
*-4.7.7
4.7.8
08/08/2023
AI ChatBot <= 4.5.5 – Authenticated (Administrator+) Stored Cross-Site Scripting
The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-4.5.5
4.5.6
25/05/2023
AI ChatBot <= 4.5.4 – Authenticated (Administrator+) Stored Cross-Site Scripting
The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-4.5.4
4.5.5
22/05/2023
AI ChatBot <= 4.6.0 – Authenticated (Administrator+) Stored Cross-Site Scripting
The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings on the 'language' tab in versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible…
*-4.6.0
4.6.1
22/05/2023
ChatBot <= 4.4.4 – Unauthenticated Stored Cross-Site Scripting via Cross-Site Request Forgery
The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 4.4.4 due to insufficient input sanitization and output escaping and a lack of nonce check on the…
*-4.4.4
4.4.5
20/04/2023
ChatBot <= 4.4.8 – Authenticated (Subscriber+) Stored Cross-Site Scripting via openai_settings_option_callback
The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘openai_settings_option_callback’ function in versions up to, and including, 4.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-4.4.8
4.4.9
12/04/2023
AI ChatBot <= 4.4.9 – Authenticated (Administrator+) Stored Cross-Site Scripting
The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-4.4.9
4.5.1
12/04/2023
ChatBot <= 4.4.8 – Unauthenticated Stored Cross-Site Scripting in Admin Dashboard
The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting in the Admin Dashboard in versions up to, and including, 4.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers (leveraging…
*-4.4.8
4.4.9
12/04/2023
ChatBot <= 4.4.6 – Unauthenticated PHP Object Injection via Cookies
The ChatBot plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.4.6 via deserialization of untrusted input from cookies This allows unauthenticated attackers to inject a PHP Object. No POP chain is…
*-4.4.6
4.4.7
12/04/2023
AI ChatBot <= 4.4.7 – Missing Authorization on openai_settings_option_callback
The AI ChatBot plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the openai_settings_option_callback function in versions up to, and including, 4.4.7. This makes it possible for subscriber-level attackers to change…
*-4.4.7
4.4.8
29/03/2023
ChatBot <= 4.3.0 – Authenticated (Admin+) Cross-Site Scripting
The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘qlcd_wp_chatbot_email_sub’ parameter in versions up to, and including, 4.3.0 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to…
*-4.3.0
4.3.1
27/01/2023
ChatBot <= 4.2.8 – Cross-Site Request Forgery to Stored Cross-Site Scripting and Settings Reset
The ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.8. This is due to missing or incorrect nonce validation on the 'qcld_wb_chatbot_save_options' function. This makes it possible for unauthenticated attackers…
*-4.2.8
4.2.9
27/01/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.