Filtered by vendor Quantumcloud
Subscriptions
Filtered by product Wpbot
Subscriptions
Total
27 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2022-47613 | 1 Quantumcloud | 1 Wpbot | 2025-05-12 | 5.9 Medium |
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud AI ChatBot plugin <= 4.3.0 versions. | ||||
CVE-2023-2811 | 1 Quantumcloud | 1 Wpbot | 2025-05-12 | 4.8 Medium |
The AI ChatBot WordPress plugin before 4.5.6 does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks to all admin when setting chatbot and all client when using chatbot | ||||
CVE-2023-1011 | 1 Quantumcloud | 1 Wpbot | 2025-05-12 | 6.1 Medium |
The AI ChatBot WordPress plugin before 4.4.5 does not escape most of its settings before outputting them back in the dashboard, and does not have a proper CSRF check, allowing attackers to make a logged in admin set XSS payloads in them. | ||||
CVE-2023-5254 | 1 Quantumcloud | 1 Wpbot | 2025-05-12 | 5.3 Medium |
The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9 via the qcld_wb_chatbot_check_user function. This can allow unauthenticated attackers to extract sensitive data including confirmation as to whether a user name exists on the site as well as order information for existing users. | ||||
CVE-2023-3175 | 1 Quantumcloud | 1 Wpbot | 2025-05-12 | 4.8 Medium |
The AI ChatBot WordPress plugin before 4.6.1 does not adequately escape some settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | ||||
CVE-2024-0453 | 1 Quantumcloud | 1 Wpbot | 2025-05-12 | 5 Medium |
The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete files from a linked OpenAI account. | ||||
CVE-2024-0451 | 1 Quantumcloud | 1 Wpbot | 2025-05-12 | 5 Medium |
The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the openai_file_list_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to list files existing in a linked OpenAI account. |