CVE-2023-4254: Chatbot < 4.7.8 - Admin+ Stored XSS in Language Settings
Published Sep 4, 2023
·Updated
The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
2 affected components
QuantumCloud Ai Chatbot Wordpress<4.7.8
QuantumCloud Wpbot Wordpress<4.7.8
Event History
Sep 4, 2023
CVE Published
via MITRE·11:26 AM
Data Sourced
via MITRE·11:26 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-4254.
2
What is the affected software?
The affected software is the AI ChatBot WordPress plugin before version 4.7.8.
3
What is the severity level of CVE-2023-4254?
The severity level of CVE-2023-4254 is medium (4.8).
4
What is the risk of CVE-2023-4254?
CVE-2023-4254 allows high privilege users to perform Stored Cross-Site Scripting attacks.
5
How can I fix CVE-2023-4254?
To fix CVE-2023-4254, update the AI ChatBot WordPress plugin to version 4.7.8 or later.