First published: Mon May 08 2023(Updated: )
The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Object Injection when a suitable gadget is present on the blog
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Quantumcloud Ai Chatbot | <4.4.7 | |
<4.4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-1650.
The severity of CVE-2023-1650 is critical with a severity value of 9.8.
The affected software for CVE-2023-1650 is the AI ChatBot WordPress plugin version up to 4.4.7.
CVE-2023-1650 allows unauthenticated users to unserialize user input from cookies via an AJAX action, potentially leading to PHP Object Injection.
To fix CVE-2023-1650, update the AI ChatBot WordPress plugin to version 4.4.7 or above.