First published: Mon Jun 19 2023(Updated: )
The AI ChatBot WordPress plugin before 4.5.5 does not sanitize and escape its settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Quantumcloud Ai Chatbot | <4.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2742 is a vulnerability in the AI ChatBot WordPress plugin before version 4.5.5 that allows high-privilege users to perform Cross-Site Scripting attacks.
CVE-2023-2742 affects the AI ChatBot WordPress plugin before version 4.5.5 by not properly sanitizing and escaping its settings, which can enable Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2023-2742 has a severity keyword of 'medium' and a severity value of 4.8.
To fix CVE-2023-2742, make sure to update the AI ChatBot WordPress plugin to version 4.5.5 or above, as this vulnerability has been patched in that version.
CVE-2023-2742 is associated with CWE-79, which is the Weaknesses in OWASP Top Ten (2013) category.