CVE-2023-2811: AI ChatBot < 4.5.6 - Admin+ Stored Cross-Site Scripting
Published Jun 19, 2023
·Updated
The AI ChatBot WordPress plugin before 4.5.6 does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks to all admin when setting chatbot and all client when using chatbot
Affected Software
2 affected components
QuantumCloud Ai Chatbot Wordpress<4.5.6
QuantumCloud Wpbot Wordpress<4.5.6
Event History
Jun 19, 2023
CVE Published
via MITRE·10:52 AM
Data Sourced
via MITRE·10:52 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-2811.
2
What is the severity of CVE-2023-2811?
CVE-2023-2811 has a severity level of medium with a value of 4.8.
3
What is the affected software?
The affected software is the AI ChatBot WordPress plugin before version 4.5.6.
4
What is the risk of CVE-2023-2811?
CVE-2023-2811 allows high privilege users to perform Stored Cross-Site Scripting attacks to all admin when setting chatbot and all client when using chatbot.
5
How can I fix the CVE-2023-2811 vulnerability?
To fix the CVE-2023-2811 vulnerability, update the AI ChatBot WordPress plugin to version 4.5.6 or later.