plugin

Conversational Forms Vulnerabilities

8 known security issues reported for the Conversational Forms WordPress plugin. Most recent disclosed Jan 9, 2025.

1 high 3 medium

Running Conversational Forms on your site? Check whether your installed version is affected.

Scan your site free

ChatBot Conversational Forms [conversational-forms] < 1.4.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ChatBot for WordPress - WPBot Conversational Forms for ChatBot allows Stored XSS.This issue affects Conversational Forms for ChatBot: from n/a through 1.4.2.

Affected:
up to 1.4.3
Fixed in:
1.4.3
Disclosed:
Jan 9, 2025

CVE-2025-22813 on NVD →

Conversational Forms for ChatBot <= 1.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Conversational Forms for ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web...

CVSS:
6.4
Affected:
up to 1.4.2
Fixed in:
1.4.3
Disclosed:
Jan 7, 2025

CVE-2025-22813 on NVD →

ChatBot Conversational Forms [conversational-forms] < 1.3.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Stored XSS.This issue affects Conversational Forms for ChatBot: from n/a through 1.2.0.

Affected:
up to 1.3.0
Fixed in:
1.3.0
Disclosed:
May 6, 2024

CVE-2024-34380 on NVD →

Conversational Forms for ChatBot <= 1.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The ChatBot Conversational Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...

CVSS:
4.4
Affected:
up to 1.2.0
Fixed in:
1.3.0
Disclosed:
May 3, 2024

CVE-2024-34380 on NVD →

Conversational Forms for ChatBot <= 1.1.8 - Unauthenticated Arbitrary File Download

high

The ChatBot Conversational Forms plugin for WordPress is vulnerable to Arbitrary File Download in all versions up to, and including, 1.1.8. This makes it possible for unauthenticated attackers to download arbitrary files from the server which may contain sensitive information.

CVSS:
7.5
Affected:
up to 1.1.8
Fixed in:
1.2.0
Disclosed:
Apr 22, 2024

CVE-2024-32729 on NVD →

ChatBot Conversational Forms [conversational-forms] < 1.1.7

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud Conversational Forms for ChatBot plugin <= 1.1.6 versions.

Affected:
up to 1.1.7
Fixed in:
1.1.7
Disclosed:
Apr 6, 2023

CVE-2023-23981 on NVD →

Conversational Forms for ChatBot <= 1.1.6 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Conversational Forms for ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via a form name in versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to inje...

CVSS:
5.5
Affected:
up to 1.1.6
Fixed in:
1.1.7
Disclosed:
Jan 20, 2023

CVE-2023-23981 on NVD →

ChatBot Conversational Forms [conversational-forms] < 1.2.0

unknown
Affected:
up to 1.2.0
Fixed in:
1.2.0

CVE-2024-32729 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database