ZeroHour

CVE-2023-1660

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p19
Published
()
Modified
Description

The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in a function hooked to init, allowing unauthenticated users to update some settings, leading to Stored XSS due to the lack of escaping when outputting them in the admin dashboard

Vendors
quantumcloud
Products
wpbot
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.