CVE-2023-2742: AI ChatBot < 4.5.5 - Admin+ Stored Cross-Site Scripting
The AI ChatBot WordPress plugin before 4.5.5 does not sanitize and escape its settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-2742?
CVE-2023-2742 is a vulnerability in the AI ChatBot WordPress plugin before version 4.5.5 that allows high-privilege users to perform Cross-Site Scripting attacks.
How does CVE-2023-2742 affect the AI ChatBot WordPress plugin?
CVE-2023-2742 affects the AI ChatBot WordPress plugin before version 4.5.5 by not properly sanitizing and escaping its settings, which can enable Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
What is the severity of CVE-2023-2742?
CVE-2023-2742 has a severity keyword of 'medium' and a severity value of 4.8.
How can I fix CVE-2023-2742?
To fix CVE-2023-2742, make sure to update the AI ChatBot WordPress plugin to version 4.5.5 or above, as this vulnerability has been patched in that version.
What is the CWE of CVE-2023-2742?
CVE-2023-2742 is associated with CWE-79, which is the Weaknesses in OWASP Top Ten (2013) category.