ZeroHour

CVE-2023-1650

PoC
CVSS 3.1
9.8 critical
EPSS
34%p98
Published
()
Modified
Description

The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Object Injection when a suitable gadget is present on the blog

Vendors
quantumcloud
Products
wpbot
Ecosystems
WordPress
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.