CVE-2023-3175: AI ChatBot < 4.6.1 - Admin+ Stored Cross-Site Scripting
Published Jul 10, 2023
·Updated
The AI ChatBot WordPress plugin before 4.6.1 does not adequately escape some settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed.
Affected Software
2 affected components
QuantumCloud Ai Chatbot Wordpress<4.6.1
QuantumCloud Wpbot Wordpress<4.6.1
Event History
Jul 10, 2023
CVE Published
via MITRE·12:40 PM
Data Sourced
via MITRE·12:40 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-3175.
2
What is the severity of CVE-2023-3175?
The severity of CVE-2023-3175 is medium.
3
What is the affected software of CVE-2023-3175?
The affected software of CVE-2023-3175 is the AI ChatBot WordPress plugin before version 4.6.1.
4
What is the description of CVE-2023-3175?
CVE-2023-3175 is a vulnerability in the AI ChatBot WordPress plugin before version 4.6.1 that allows high-privilege users to perform Cross-Site Scripting attacks.
5
How can I fix CVE-2023-3175?
To fix CVE-2023-3175, update the AI ChatBot WordPress plugin to version 4.6.1 or later.