plugin

Auyautochat For Wp Vulnerabilities

4 known security issues reported for the Auyautochat For Wp WordPress plugin. Most recent disclosed Nov 25, 2025.

1 high 1 medium

Running Auyautochat For Wp on your site? Check whether your installed version is affected.

Scan your site free

Autochat Automatic Conversation [auyautochat-for-wp] <= 1.1.9 (unfixed)

unknown

[en] The Autochat Automatic Conversation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_auycht_saveCid' AJAX endpoint in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to connect and disconn...

Affected:
up to 1.1.9
Fix:
No patched version reported
Disclosed:
Nov 25, 2025

CVE-2025-12043 on NVD →

Autochat Automatic Conversation <= 1.1.9 - Missing Authorization to Unauthenticated Settings Update

medium

The Autochat Automatic Conversation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_auycht_saveCid' AJAX endpoint in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to connect and disconnect t...

CVSS:
5.3
Affected:
up to 1.1.9
Fix:
No patched version reported
Disclosed:
Nov 24, 2025

CVE-2025-12043 on NVD →

Autochat Automatic Conversation [auyautochat-for-wp] <= 1.1.9 (unfixed + closed)

unknown

[en] The Autochat Automatic Conversation WordPress plugin through 1.1.7 does not sanitise and escape user input before outputting it back on the page, leading to a cross-site Scripting attack.

Affected:
up to 1.1.9
Fix:
No patched version reported
Disclosed:
Jul 17, 2023

CVE-2023-3041 on NVD →

Autochat Automatic Conversation <= 1.1.9 - Unauthenticated Stored Cross-Site Scripting

high

The Autochat Automatic Conversation plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenev...

CVSS:
7.2
Affected:
up to 1.1.9
Fix:
No patched version reported
Disclosed:
Jun 26, 2023

CVE-2023-3041 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database