Extension WordPress

Vulnérabilités WPBot – AI ChatBot for Live Support, Lead Generation, AI Services, page 2

Cette page rassemble les failles publiées pour WPBot – AI ChatBot for Live Support, Lead Generation, AI Services, leurs plages de versions affectées et les correctifs signalés dans la base locale.

44Vulnérabilités
5Critiques
44Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

44 fiches

CVE-2024-0451 Moyenne · 5,0
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 5.3.4 – Missing Authorization via openai_file_list_callback

The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the openai_file_list_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers,…

Versions affectées

*-5.3.4

Correctif

5.3.6

Publication

21/05/2024

CVE-2024-22309 Critique · 9,8
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot <= 5.1.0 – Unauthenticated PHP Object Injection

The ChatBot with AI plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1.0 via deserialization of untrusted input via the last_five_prompt cookies. This makes it possible for unauthenticated attackers to…

Versions affectées

*-5.1.0

Correctif

5.1.1

Publication

19/01/2024

CVE-2023-5606 Moyenne · 4,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot 4.8.6 – 4.9.6 – Authenticated (Administrator+) Stored Cross-Site Scripting in FAQ Builder

The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions 4.8.6 through 4.9.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and…

Versions affectées

4.8.6-4.9.6

Correctif

4.9.7

Publication

01/11/2023

CVE-2023-5254 Moyenne · 5,3
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.8.9 – Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_user

The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9 via the qcld_wb_chatbot_check_user function. This can allow unauthenticated attackers to extract sensitive data including confirmation as to whether a user…

Versions affectées

*-4.8.9

Correctif

4.9.1

Publication

11/10/2023

CVE-2023-5533 Moyenne · 5,3
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.8.9 and 4.9.2 – Missing Authorization on AJAX actions

The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks on the corresponding functions in versions up to, and including, 4.8.9 as well as 4.9.2. This makes it possible…

Versions affectées

*-4.8.9, 4.9.2

Correctif

4.9.1, 4.9.3

Publication

11/10/2023

CVE-2023-5534 Moyenne · 4,3
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.8.9 and 4.9.2 – Cross-Site Request Forgery on AJAX actions

The AI ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.9 and 4.9.2. This is due to missing or incorrect nonce validation on the corresponding functions. This makes it possible…

Versions affectées

*-4.8.9, 4.9.2

Correctif

4.9.1, 4.9.3

Publication

11/10/2023

CVE-2023-5212 Critique · 9,6
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.8.9 and 4.9.2- Authenticated (Subscriber+) Arbitrary File Deletion via qcld_openai_delete_training_file

The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as well as version 4.9.2. This makes it possible for authenticated attackers with subscriber privileges to delete arbitrary files…

Versions affectées

*-4.8.9, 4.9.2

Correctif

4.9.1, 4.9.3

Publication

11/10/2023

CVE-2023-5204 Critique · 9,8
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.8.9 – Unauthenticated SQL Injection via qc_wpbo_search_response

The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

Versions affectées

*-4.8.9

Correctif

4.9.1

Publication

11/10/2023

CVE-2023-5241 Critique · 9,6
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.8.9 and 4.9.2 – Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_file

The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to append "

Versions affectées

*-4.8.9, 4.9.2

Correctif

4.9.1, 4.9.3

Publication

11/10/2023

CVE-2023-44993 Moyenne · 5,3
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot <= 4.7.8 – Cross-Site Request Forgery via qc_wp_latest_update_check

The ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.7.8. This is due to missing or incorrect nonce validation on the qc_wp_latest_update_check function. This makes it possible for unauthenticated attackers…

Versions affectées

*-4.7.8

Correctif

4.7.9

Publication

03/10/2023

CVE-2023-4253 Moyenne · 4,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot <= 4.7.7 – Authenticated (Administrator+) Stored Cross-Site Scripting in FAQ Builder

The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions up to, and including, 4.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…

Versions affectées

*-4.7.7

Correctif

4.7.8

Publication

08/08/2023

CVE-2023-4254 Moyenne · 4,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot 4.7.7 – Authenticated (Administrator+) Stored Cross-Site Scripting in Language Settings

The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via Language Settings in versions up to, and including, 4.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions…

Versions affectées

*-4.7.7

Correctif

4.7.8

Publication

08/08/2023

CVE-2023-2811 Moyenne · 4,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.5.5 – Authenticated (Administrator+) Stored Cross-Site Scripting

The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-4.5.5

Correctif

4.5.6

Publication

25/05/2023

CVE-2023-2742 Moyenne · 4,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.5.4 – Authenticated (Administrator+) Stored Cross-Site Scripting

The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-4.5.4

Correctif

4.5.5

Publication

22/05/2023

CVE-2023-3175 Moyenne · 4,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.6.0 – Authenticated (Administrator+) Stored Cross-Site Scripting

The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings on the 'language' tab in versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-4.6.0

Correctif

4.6.1

Publication

22/05/2023

CVE-2023-1011 Moyenne · 6,1
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot <= 4.4.4 – Unauthenticated Stored Cross-Site Scripting via Cross-Site Request Forgery

The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 4.4.4 due to insufficient input sanitization and output escaping and a lack of nonce check on the…

Versions affectées

*-4.4.4

Correctif

4.4.5

Publication

20/04/2023

CVE-2023-1651 Moyenne · 6,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot <= 4.4.8 – Authenticated (Subscriber+) Stored Cross-Site Scripting via openai_settings_option_callback

The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘openai_settings_option_callback’ function in versions up to, and including, 4.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-4.4.8

Correctif

4.4.9

Publication

12/04/2023

CVE-2023-1649 Moyenne · 4,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.4.9 – Authenticated (Administrator+) Stored Cross-Site Scripting

The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-4.4.9

Correctif

4.5.1

Publication

12/04/2023

CVE-2023-1660 Moyenne · 6,5
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot <= 4.4.8 – Unauthenticated Stored Cross-Site Scripting in Admin Dashboard

The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting in the Admin Dashboard in versions up to, and including, 4.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers (leveraging…

Versions affectées

*-4.4.8

Correctif

4.4.9

Publication

12/04/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités