The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.
Metrics
Affected Vendors & Products
References
History
Tue, 27 May 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Webdigit
Webdigit chatbot With Chatgpt |
|
Weaknesses | CWE-89 | |
CPEs | cpe:2.3:a:webdigit:chatbot_with_chatgpt:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Webdigit
Webdigit chatbot With Chatgpt |
Tue, 20 Aug 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Smartsearchwp
Smartsearchwp chatbot With Chatgpt Wordpress |
|
CPEs | cpe:2.3:a:smartsearchwp:chatbot_with_chatgpt_wordpress:*:*:*:*:*:*:*:* | |
Vendors & Products |
Smartsearchwp
Smartsearchwp chatbot With Chatgpt Wordpress |
|
Metrics |
cvssV3_1
|
Tue, 20 Aug 2024 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot. | |
Title | SmartSearch WP <= 2.4.4 - Unauthenticated SQLi | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2024-08-20T06:00:03.192Z
Updated: 2024-08-20T18:50:30.236Z
Reserved: 2024-07-17T18:48:10.771Z
Link: CVE-2024-6847

Updated: 2024-08-20T18:50:25.304Z

Status : Analyzed
Published: 2024-08-20T06:15:05.470
Modified: 2025-05-27T20:49:37.690
Link: CVE-2024-6847

No data.