CVE-2023-1649: ChatBot < 4.5.1 - Admin+ Stored XSS
Published May 8, 2023
·Updated
The AI ChatBot WordPress plugin before 4.5.1 does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
2 affected components
QuantumCloud Ai Chatbot Wordpress<4.5.1
QuantumCloud Wpbot Wordpress<4.5.1
Event History
May 8, 2023
CVE Published
via MITRE·01:58 PM
Data Sourced
via MITRE·01:58 PM
DescriptionWeakness
Data Sourced
02:15 PM
DescriptionWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-1649.
2
What is the severity of CVE-2023-1649?
The severity of CVE-2023-1649 is medium with a severity value of 4.8.
3
What is the affected software?
The affected software is the AI ChatBot WordPress plugin before version 4.5.1.
4
What is the impact of CVE-2023-1649?
CVE-2023-1649 could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks.
5
How can I mitigate the vulnerability?
To mitigate the vulnerability, update the AI ChatBot WordPress plugin to version 4.5.1 or higher.