Extension WordPress

Vulnérabilités WPBot – AI ChatBot for Live Support, Lead Generation, AI Services, page 3

Cette page rassemble les failles publiées pour WPBot – AI ChatBot for Live Support, Lead Generation, AI Services, leurs plages de versions affectées et les correctifs signalés dans la base locale.

44Vulnérabilités
5Critiques
44Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

44 fiches

CVE-2023-1650 Critique · 9,8
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot <= 4.4.6 – Unauthenticated PHP Object Injection via Cookies

The ChatBot plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.4.6 via deserialization of untrusted input from cookies This allows unauthenticated attackers to inject a PHP Object. No POP chain is…

Versions affectées

*-4.4.6

Correctif

4.4.7

Publication

12/04/2023

Vulnérabilité Moyenne · 5,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 4.4.7 – Missing Authorization on openai_settings_option_callback

The AI ChatBot plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the openai_settings_option_callback function in versions up to, and including, 4.4.7. This makes it possible for subscriber-level attackers to change…

Versions affectées

*-4.4.7

Correctif

4.4.8

Publication

29/03/2023

CVE-2022-47613 Moyenne · 4,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot <= 4.3.0 – Authenticated (Admin+) Cross-Site Scripting

The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘qlcd_wp_chatbot_email_sub’ parameter in versions up to, and including, 4.3.0 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to…

Versions affectées

*-4.3.0

Correctif

4.3.1

Publication

27/01/2023

CVE-2023-24415 Moyenne · 5,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot <= 4.2.8 – Cross-Site Request Forgery to Stored Cross-Site Scripting and Settings Reset

The ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.8. This is due to missing or incorrect nonce validation on the 'qcld_wb_chatbot_save_options' function. This makes it possible for unauthenticated attackers…

Versions affectées

*-4.2.8

Correctif

4.2.9

Publication

27/01/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités