WPBot <= 8.5.9 - Unauthenticated Sensitive Information Exposure in 'wpbot_send_email_transcript' AJAX Action
medium
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and as...
- CVSS:
- 5.3
- Affected:
- up to 8.5.9
- Fixed in:
- 8.6.0
- Disclosed:
- Jul 27, 2026
CVE-2026-16773 on NVD →
WPBot <= 8.5.9 - Missing Authorization to Unauthenticated Email Relay via wpcs_send_email AJAX Action
medium
The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handler. This is due to the wpcs_send_email() function being registered on both wp_ajax_wpcs_send_email and wp_ajax_nopriv_wpcs_send_email with no nonce verification, capability...
- CVSS:
- 5.3
- Affected:
- up to 8.5.9
- Fixed in:
- 8.6.0
- Disclosed:
- Jul 27, 2026
CVE-2026-16774 on NVD →
WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameter
medium
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attack...
- CVSS:
- 5.3
- Affected:
- up to 8.5.6
- Fixed in:
- 8.5.7
- Disclosed:
- Jul 15, 2026
CVE-2026-15106 on NVD →
WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Function
medium
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attacker...
- CVSS:
- 4.3
- Affected:
- up to 8.5.6
- Fixed in:
- 8.5.7
- Disclosed:
- Jul 15, 2026
CVE-2026-15610 on NVD →
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 8.3.7 - Unauthenticated Stored Cross-Site Scripting
high
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.3.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- CVSS:
- 7.2
- Affected:
- up to 8.3.7
- Fixed in:
- 8.3.8
- Disclosed:
- Jul 6, 2026
CVE-2026-57363 on NVD →
WPBot AI ChatBot <= 8.5.1 - Authenticated (Administrator+) SQL Injection
medium
The WPBot AI ChatBot plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access a...
- CVSS:
- 4.9
- Affected:
- up to 8.5.1
- Fixed in:
- 8.5.2
- Disclosed:
- Jul 6, 2026
CVE-2026-14189 on NVD →
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 8.3.2 - Reflected Cross-Site Scripting
medium
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 8.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scri...
- CVSS:
- 6.1
- Affected:
- up to 8.3.2
- Fixed in:
- 8.3.3
- Disclosed:
- Jul 1, 2026
CVE-2026-57362 on NVD →
WPBot <= 8.4.9 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter
high
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conversation' parameter in all versions up to, and including, 8.4.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated atta...
- CVSS:
- 7.2
- Affected:
- up to 8.4.9
- Fixed in:
- 8.5.0
- Disclosed:
- Jun 30, 2026
CVE-2026-13731 on NVD →
WPBot AI ChatBot <= 8.1.0 - Missing Authorization
medium
The WPBot AI ChatBot plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 8.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 8.1.0
- Fixed in:
- 8.2.0
- Disclosed:
- Jun 30, 2026
CVE-2026-14185 on NVD →
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 7.9.7 - Missing Authorization
medium
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.9.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform...
- CVSS:
- 4.3
- Affected:
- up to 7.9.7
- Fixed in:
- 7.9.9
- Disclosed:
- Apr 23, 2026
CVE-2026-40788 on NVD →
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 7.7.9 - Unauthenticated SQL Injection
high
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthent...
- CVSS:
- 7.5
- Affected:
- up to 7.7.9
- Fixed in:
- 7.8.0
- Disclosed:
- Mar 20, 2026
CVE-2026-32499 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 7.4.0
unknown
[en] Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 7.3.9.
- Affected:
- up to 7.4.0
- Fixed in:
- 7.4.0
- Disclosed:
- Nov 13, 2025
CVE-2025-64277 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] <= 7.3.0 (unfixed)
unknown
[en] Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 7.3.0.
- Affected:
- up to 7.3.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 27, 2025
CVE-2025-62952 on NVD →
ChatBot <= 7.7.3 - Missing Authorization
medium
The ChatBot plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.7.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 7.7.3
- Fixed in:
- 7.7.4
- Disclosed:
- Oct 13, 2025
CVE-2025-62952 on NVD →
ChatBot <= 7.3.9 - Missing Authorization
medium
The AI ChatBot – WPBot for Live Support and Lead Generation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.3.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 7.3.9
- Fixed in:
- 7.4.0
- Disclosed:
- Oct 12, 2025
CVE-2025-64277 on NVD →
AI ChatBot for WordPress <= 7.1.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and a...
- CVSS:
- 4.4
- Affected:
- up to 7.0.0
- Fixed in:
- 7.1.0
- Disclosed:
- Aug 19, 2025
CVE-2025-9111 on NVD →
ChatBot <= 6.7.3 - Missing Authorization
medium
The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.7.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 5.4
- Affected:
- up to 6.7.3
- Fixed in:
- 6.7.5
- Disclosed:
- Jun 27, 2025
CVE-2025-53200 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 6.7.5
unknown
[en] Missing Authorization vulnerability in QuantumCloud ChatBot allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ChatBot: from n/a through 6.7.3.
- Affected:
- up to 6.7.5
- Fixed in:
- 6.7.5
- Disclosed:
- Jun 27, 2025
CVE-2025-53200 on NVD →
AI ChatBot for WordPress – WPBot <= 6.2.3 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and a...
- CVSS:
- 4.4
- Affected:
- up to 6.2.3
- Fixed in:
- 6.2.4
- Disclosed:
- Mar 3, 2025
CVE-2025-0329 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 6.3.6
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in QuantumCloud ChatBot allows PHP Local File Inclusion. This issue affects ChatBot: from n/a through 6.3.5.
- Affected:
- up to 6.3.6
- Fixed in:
- 6.3.6
- Disclosed:
- Feb 25, 2025
CVE-2025-26932 on NVD →
ChatBot <= 6.3.5 - Authenticated (Contributor+) Local File Inclusion
high
The ChatBot plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.3.5. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This c...
- CVSS:
- 8.8
- Affected:
- up to 6.3.5
- Fixed in:
- 6.3.6
- Disclosed:
- Feb 23, 2025
CVE-2025-26932 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 5.5.8
unknown
[en] The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions...
- Affected:
- up to 5.5.8
- Fixed in:
- 5.5.8
- Disclosed:
- Jul 17, 2024
CVE-2024-6669 on NVD →
AI ChatBot for WordPress – WPBot <= 5.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and a...
- CVSS:
- 5.5
- Affected:
- up to 5.5.7
- Fixed in:
- 5.5.8
- Disclosed:
- Jul 16, 2024
CVE-2024-6669 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 5.3.6
unknown
[en] The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_upload_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload fil...
- Affected:
- up to 5.3.6
- Fixed in:
- 5.3.6
- Disclosed:
- May 22, 2024
CVE-2024-0452 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 5.3.6
unknown
[en] The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete fil...
- Affected:
- up to 5.3.6
- Fixed in:
- 5.3.6
- Disclosed:
- May 22, 2024
CVE-2024-0453 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 5.3.6
unknown
[en] The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the openai_file_list_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to list files existin...
- Affected:
- up to 5.3.6
- Fixed in:
- 5.3.6
- Disclosed:
- May 22, 2024
CVE-2024-0451 on NVD →
AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_delete_callback
medium
The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete files fr...
- CVSS:
- 5
- Affected:
- up to 5.3.4
- Fixed in:
- 5.3.6
- Disclosed:
- May 21, 2024
CVE-2024-0453 on NVD →
AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_list_callback
medium
The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the openai_file_list_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to list files existing in...
- CVSS:
- 5
- Affected:
- up to 5.3.4
- Fixed in:
- 5.3.6
- Disclosed:
- May 21, 2024
CVE-2024-0451 on NVD →
AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_upload_callback
medium
The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_upload_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files to...
- CVSS:
- 5
- Affected:
- up to 5.3.4
- Fixed in:
- 5.3.6
- Disclosed:
- May 21, 2024
CVE-2024-0452 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 5.1.1
unknown
[en] Deserialization of Untrusted Data vulnerability in QuantumCloud ChatBot with AI.This issue affects ChatBot with AI: from n/a through 5.1.0.
- Affected:
- up to 5.1.1
- Fixed in:
- 5.1.1
- Disclosed:
- Jan 24, 2024
CVE-2024-22309 on NVD →
ChatBot <= 5.1.0 - Unauthenticated PHP Object Injection
critical
The ChatBot with AI plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1.0 via deserialization of untrusted input via the last_five_prompt cookies. This makes it possible for unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugi...
- CVSS:
- 9.8
- Affected:
- up to 5.1.0
- Fixed in:
- 5.1.1
- Disclosed:
- Jan 19, 2024
CVE-2024-22309 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.7.9
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud AI ChatBot.This issue affects AI ChatBot: from n/a through 4.7.8.
- Affected:
- up to 4.7.9
- Fixed in:
- 4.7.9
- Disclosed:
- Dec 19, 2023
CVE-2023-48741 on NVD →
ChatBot <= 4.7.8 - Authenticated (Administrator+) SQL Injection
high
The AI ChatBot plugin for WordPress is vulnerable to SQL Injection via the orderby parameter in all versions up to, and including, 4.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for administrators to append addition...
- CVSS:
- 7.2
- Affected:
- up to 4.7.8
- Fixed in:
- 4.7.9
- Disclosed:
- Nov 23, 2023
CVE-2023-48741 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.9.7
unknown
[en] The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions 4.8.6 through 4.9.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts...
- Affected:
- up to 4.9.7
- Fixed in:
- 4.9.7
- Disclosed:
- Nov 2, 2023
CVE-2023-5606 on NVD →
ChatBot 4.8.6 - 4.9.6 - Authenticated (Administrator+) Stored Cross-Site Scripting in FAQ Builder
medium
The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions 4.8.6 through 4.9.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pa...
- CVSS:
- 4.4
- Affected:
- 4.8.6 – 4.9.6
- Fixed in:
- 4.9.7
- Disclosed:
- Nov 1, 2023
CVE-2023-5606 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.9.3
unknown
- Affected:
- up to 4.9.3
- Fixed in:
- 4.9.3
- Disclosed:
- Oct 20, 2023
CVE-2023-5646 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.9.3
unknown
- Affected:
- up to 4.9.3
- Fixed in:
- 4.9.3
- Disclosed:
- Oct 20, 2023
CVE-2023-5647 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.9.3
unknown
- Affected:
- up to 4.9.3
- Fixed in:
- 4.9.3
- Disclosed:
- Oct 20, 2023
CVE-2023-5655 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.9.3
unknown
- Affected:
- up to 4.9.3
- Fixed in:
- 4.9.3
- Disclosed:
- Oct 20, 2023
CVE-2023-5656 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.9.1
unknown
[en] The AI ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.9 and 4.9.2. This is due to missing or incorrect nonce validation on the corresponding functions. This makes it possible for unauthenticated attackers to invoke those functions via a forged request...
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.1
- Disclosed:
- Oct 20, 2023
CVE-2023-5534 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.9.1
unknown
[en] The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks on the corresponding functions in versions up to, and including, 4.8.9 as well as 4.9.2. This makes it possible for unauthenticated attackers to perform some of those actions that were intended fo...
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.1
- Disclosed:
- Oct 20, 2023
CVE-2023-5533 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.9.1
unknown
[en] The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9 via the qcld_wb_chatbot_check_user function. This can allow unauthenticated attackers to extract sensitive data including confirmation as to whether a user name exists on the site as well as ord...
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.1
- Disclosed:
- Oct 19, 2023
CVE-2023-5254 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.9.1
unknown
[en] The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append...
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.1
- Disclosed:
- Oct 19, 2023
CVE-2023-5204 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.9.1
unknown
[en] The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as well as version 4.9.2. This makes it possible for authenticated attackers with subscriber privileges to delete arbitrary files on the server, which makes it possible to take over affected sites a...
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.1
- Disclosed:
- Oct 19, 2023
CVE-2023-5212 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.9.1
unknown
[en] The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to append "<?php" to any existing file on the server resulting in potential DoS when appended to c...
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.1
- Disclosed:
- Oct 19, 2023
CVE-2023-5241 on NVD →
AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_response
critical
The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append addit...
- CVSS:
- 9.8
- Affected:
- up to 4.8.9
- Fixed in:
- 4.9.1
- Disclosed:
- Oct 11, 2023
CVE-2023-5204 on NVD →
AI ChatBot <= 4.8.9 and 4.9.2 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_file
critical
The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to append "<?php" to any existing file on the server resulting in potential DoS when appended to critic...
- CVSS:
- 9.6
- Affected:
- up to 4.8.9, 4.9.2 – 4.9.2
- Fixed in:
- 4.9.1
- Disclosed:
- Oct 11, 2023
CVE-2023-5241 on NVD →
AI ChatBot <= 4.8.9 and 4.9.2- Authenticated (Subscriber+) Arbitrary File Deletion via qcld_openai_delete_training_file
critical
The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as well as version 4.9.2. This makes it possible for authenticated attackers with subscriber privileges to delete arbitrary files on the server, which makes it possible to take over affected sites as wel...
- CVSS:
- 9.6
- Affected:
- up to 4.8.9, 4.9.2 – 4.9.2
- Fixed in:
- 4.9.1
- Disclosed:
- Oct 11, 2023
CVE-2023-5212 on NVD →
AI ChatBot <= 4.8.9 - Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_user
medium
The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9 via the qcld_wb_chatbot_check_user function. This can allow unauthenticated attackers to extract sensitive data including confirmation as to whether a user name exists on the site as well as order in...
- CVSS:
- 5.3
- Affected:
- up to 4.8.9
- Fixed in:
- 4.9.1
- Disclosed:
- Oct 11, 2023
CVE-2023-5254 on NVD →
AI ChatBot <= 4.8.9 and 4.9.2 - Missing Authorization on AJAX actions
medium
The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks on the corresponding functions in versions up to, and including, 4.8.9 as well as 4.9.2. This makes it possible for unauthenticated attackers to perform some of those actions that were intended for hig...
- CVSS:
- 5.3
- Affected:
- up to 4.8.9, 4.9.2 – 4.9.2
- Fixed in:
- 4.9.1
- Disclosed:
- Oct 11, 2023
CVE-2023-5533 on NVD →
AI ChatBot <= 4.8.9 and 4.9.2 - Cross-Site Request Forgery on AJAX actions
medium
The AI ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.9 and 4.9.2. This is due to missing or incorrect nonce validation on the corresponding functions. This makes it possible for unauthenticated attackers to invoke those functions via a forged request gran...
- CVSS:
- 4.3
- Affected:
- up to 4.8.9, 4.9.2 – 4.9.2
- Fixed in:
- 4.9.1
- Disclosed:
- Oct 11, 2023
CVE-2023-5534 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.7.9
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.7.8 versions.
- Affected:
- up to 4.7.9
- Fixed in:
- 4.7.9
- Disclosed:
- Oct 9, 2023
CVE-2023-44993 on NVD →
ChatBot <= 4.7.8 - Cross-Site Request Forgery via qc_wp_latest_update_check
medium
The ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.7.8. This is due to missing or incorrect nonce validation on the qc_wp_latest_update_check function. This makes it possible for unauthenticated attackers to invoke this function via a forged request granted...
- CVSS:
- 5.3
- Affected:
- up to 4.7.8
- Fixed in:
- 4.7.9
- Disclosed:
- Oct 3, 2023
CVE-2023-44993 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.7.8
unknown
[en] The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 4.7.8
- Fixed in:
- 4.7.8
- Disclosed:
- Sep 4, 2023
CVE-2023-4254 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.7.8
unknown
[en] The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 4.7.8
- Fixed in:
- 4.7.8
- Disclosed:
- Sep 4, 2023
CVE-2023-4253 on NVD →
ChatBot 4.7.7 - Authenticated (Administrator+) Stored Cross-Site Scripting in Language Settings
medium
The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via Language Settings in versions up to, and including, 4.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scr...
- CVSS:
- 4.4
- Affected:
- up to 4.7.7
- Fixed in:
- 4.7.8
- Disclosed:
- Aug 8, 2023
CVE-2023-4254 on NVD →
ChatBot <= 4.7.7 - Authenticated (Administrator+) Stored Cross-Site Scripting in FAQ Builder
medium
The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions up to, and including, 4.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scrip...
- CVSS:
- 4.4
- Affected:
- up to 4.7.7
- Fixed in:
- 4.7.8
- Disclosed:
- Aug 8, 2023
CVE-2023-4253 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.6.1
unknown
[en] The AI ChatBot WordPress plugin before 4.6.1 does not adequately escape some settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 4.6.1
- Fixed in:
- 4.6.1
- Disclosed:
- Jul 10, 2023
CVE-2023-3175 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.5.6
unknown
[en] The AI ChatBot WordPress plugin before 4.5.6 does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks to all admin when setting chatbot and all client when using chatbot
- Affected:
- up to 4.5.6
- Fixed in:
- 4.5.6
- Disclosed:
- Jun 19, 2023
CVE-2023-2811 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.5.5
unknown
[en] The AI ChatBot WordPress plugin before 4.5.5 does not sanitize and escape its settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 4.5.5
- Fixed in:
- 4.5.5
- Disclosed:
- Jun 19, 2023
CVE-2023-2742 on NVD →
AI ChatBot <= 4.5.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary...
- CVSS:
- 4.4
- Affected:
- up to 4.5.5
- Fixed in:
- 4.5.6
- Disclosed:
- May 25, 2023
CVE-2023-2811 on NVD →
AI ChatBot <= 4.6.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings on the 'language' tab in versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...
- CVSS:
- 4.4
- Affected:
- up to 4.6.0
- Fixed in:
- 4.6.1
- Disclosed:
- May 22, 2023
CVE-2023-3175 on NVD →
AI ChatBot <= 4.5.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary...
- CVSS:
- 4.4
- Affected:
- up to 4.5.4
- Fixed in:
- 4.5.5
- Disclosed:
- May 22, 2023
CVE-2023-2742 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.4.9
unknown
[en] The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in a function hooked to init, allowing unauthenticated users to update some settings, leading to Stored XSS due to the lack of escaping when outputting them in the admin dashboard
- Affected:
- up to 4.4.9
- Fixed in:
- 4.4.9
- Disclosed:
- May 8, 2023
CVE-2023-1660 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.4.7
unknown
[en] The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Object Injection when a suitable gadget is present on the blog
- Affected:
- up to 4.4.7
- Fixed in:
- 4.4.7
- Disclosed:
- May 8, 2023
CVE-2023-1650 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.4.9
unknown
[en] The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in the AJAX action responsible to update the OpenAI settings, allowing any authenticated users, such as subscriber to update them. Furthermore, due to the lack of escaping of the settings, this could also lead to Stored XSS
- Affected:
- up to 4.4.9
- Fixed in:
- 4.4.9
- Disclosed:
- May 8, 2023
CVE-2023-1651 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.4.7
unknown
[en] The AI ChatBot WordPress plugin before 4.4.5 does not escape most of its settings before outputting them back in the dashboard, and does not have a proper CSRF check, allowing attackers to make a logged in admin set XSS payloads in them.
- Affected:
- up to 4.4.7
- Fixed in:
- 4.4.7
- Disclosed:
- May 8, 2023
CVE-2023-1011 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.5.1
unknown
[en] The AI ChatBot WordPress plugin before 4.5.1 does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 4.5.1
- Fixed in:
- 4.5.1
- Disclosed:
- May 8, 2023
CVE-2023-1649 on NVD →
ChatBot <= 4.4.4 - Unauthenticated Stored Cross-Site Scripting via Cross-Site Request Forgery
medium
The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 4.4.4 due to insufficient input sanitization and output escaping and a lack of nonce check on the 'openai_settings_option_callback' function. This makes it possible for unauthenticated...
- CVSS:
- 6.1
- Affected:
- up to 4.4.4
- Fixed in:
- 4.4.5
- Disclosed:
- Apr 20, 2023
CVE-2023-1011 on NVD →
ChatBot <= 4.4.6 - Unauthenticated PHP Object Injection via Cookies
critical
The ChatBot plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.4.6 via deserialization of untrusted input from cookies This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional...
- CVSS:
- 9.8
- Affected:
- up to 4.4.6
- Fixed in:
- 4.4.7
- Disclosed:
- Apr 12, 2023
CVE-2023-1650 on NVD →
ChatBot <= 4.4.8 - Unauthenticated Stored Cross-Site Scripting in Admin Dashboard
medium
The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting in the Admin Dashboard in versions up to, and including, 4.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers (leveraging a function hooked to init that lacks authorization and...
- CVSS:
- 6.5
- Affected:
- up to 4.4.8
- Fixed in:
- 4.4.9
- Disclosed:
- Apr 12, 2023
CVE-2023-1660 on NVD →
ChatBot <= 4.4.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via openai_settings_option_callback
medium
The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘openai_settings_option_callback’ function in versions up to, and including, 4.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above,...
- CVSS:
- 6.4
- Affected:
- up to 4.4.8
- Fixed in:
- 4.4.9
- Disclosed:
- Apr 12, 2023
CVE-2023-1651 on NVD →
AI ChatBot <= 4.4.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The AI ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary...
- CVSS:
- 4.4
- Affected:
- up to 4.4.9
- Fixed in:
- 4.5.1
- Disclosed:
- Apr 12, 2023
CVE-2023-1649 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.4.8
unknown
Update the WordPress ChatBot plugin to the latest available version (at least 4.4.8).
Unknown discovered and reported this Broken Access Control vulnerability in WordPress ChatBot Plugin. This vulnerability has been fixed in version 4.4.8.
- Affected:
- up to 4.4.8
- Fixed in:
- 4.4.8
- Disclosed:
- Mar 30, 2023
AI ChatBot <= 4.4.7 - Missing Authorization on openai_settings_option_callback
medium
The AI ChatBot plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the openai_settings_option_callback function in versions up to, and including, 4.4.7. This makes it possible for subscriber-level attackers to change plugin settings.
- CVSS:
- 5.4
- Affected:
- up to 4.4.7
- Fixed in:
- 4.4.8
- Disclosed:
- Mar 29, 2023
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.4.5
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud AI ChatBot plugin <= 4.3.0 versions.
- Affected:
- up to 4.4.5
- Fixed in:
- 4.4.5
- Disclosed:
- Mar 29, 2023
CVE-2022-47613 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.4.8
unknown
The AI ChatBot plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the openai_settings_option_callback function in versions up to, and including, 4.4.7. This makes it possible for subscriber-level attackers to change plugin settings.
- Affected:
- up to 4.4.8
- Fixed in:
- 4.4.8
- Disclosed:
- Mar 29, 2023
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.3.0
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.2.8 versions.
- Affected:
- up to 4.3.0
- Fixed in:
- 4.3.0
- Disclosed:
- Feb 23, 2023
CVE-2023-24415 on NVD →
ChatBot <= 4.2.8 - Cross-Site Request Forgery to Stored Cross-Site Scripting and Settings Reset
medium
The ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.8. This is due to missing or incorrect nonce validation on the 'qcld_wb_chatbot_save_options' function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wi...
- CVSS:
- 5.4
- Affected:
- up to 4.2.8
- Fixed in:
- 4.2.9
- Disclosed:
- Jan 27, 2023
CVE-2023-24415 on NVD →
ChatBot <= 4.3.0 - Authenticated (Admin+) Cross-Site Scripting
medium
The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘qlcd_wp_chatbot_email_sub’ parameter in versions up to, and including, 4.3.0 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to inject arbitrary web scripts in page...
- CVSS:
- 4.4
- Affected:
- up to 4.3.0
- Fixed in:
- 4.3.1
- Disclosed:
- Jan 27, 2023
CVE-2022-47613 on NVD →
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 4.3.0
unknown
The plugin does not have authorisation and CSRF checks when reseting its settings via an AJAX action available to unauthenticated users, which could allow unauthenticated attackers to reset the plugin's settings
- Affected:
- up to 4.3.0
- Fixed in:
- 4.3.0
AI ChatBot – WPBot for Live Support and Lead Generation [chatbot] < 6.2.4
unknown
- Affected:
- up to 6.2.4
- Fixed in:
- 6.2.4
CVE-2025-0329 on NVD →