ChatBot Conversational Forms [conversational-forms] < 1.4.3
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ChatBot for WordPress - WPBot Conversational Forms for ChatBot allows Stored XSS.This issue affects Conversational Forms for ChatBot: from n/a through 1.4.2.
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- Jan 9, 2025
CVE-2025-22813 on NVD →
Conversational Forms for ChatBot <= 1.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Conversational Forms for ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web...
- CVSS:
- 6.4
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.3
- Disclosed:
- Jan 7, 2025
CVE-2025-22813 on NVD →
ChatBot Conversational Forms [conversational-forms] < 1.3.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Stored XSS.This issue affects Conversational Forms for ChatBot: from n/a through 1.2.0.
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.0
- Disclosed:
- May 6, 2024
CVE-2024-34380 on NVD →
Conversational Forms for ChatBot <= 1.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The ChatBot Conversational Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...
- CVSS:
- 4.4
- Affected:
- up to 1.2.0
- Fixed in:
- 1.3.0
- Disclosed:
- May 3, 2024
CVE-2024-34380 on NVD →
Conversational Forms for ChatBot <= 1.1.8 - Unauthenticated Arbitrary File Download
high
The ChatBot Conversational Forms plugin for WordPress is vulnerable to Arbitrary File Download in all versions up to, and including, 1.1.8. This makes it possible for unauthenticated attackers to download arbitrary files from the server which may contain sensitive information.
- CVSS:
- 7.5
- Affected:
- up to 1.1.8
- Fixed in:
- 1.2.0
- Disclosed:
- Apr 22, 2024
CVE-2024-32729 on NVD →
ChatBot Conversational Forms [conversational-forms] < 1.1.7
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud Conversational Forms for ChatBot plugin <= 1.1.6 versions.
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.7
- Disclosed:
- Apr 6, 2023
CVE-2023-23981 on NVD →
Conversational Forms for ChatBot <= 1.1.6 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Conversational Forms for ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via a form name in versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to inje...
- CVSS:
- 5.5
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.7
- Disclosed:
- Jan 20, 2023
CVE-2023-23981 on NVD →
ChatBot Conversational Forms [conversational-forms] < 1.2.0
unknown
- Affected:
- up to 1.2.0
- Fixed in:
- 1.2.0
CVE-2024-32729 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database