CVE-2023-5254: AI ChatBot <= 4.8.9 - Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_user
The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9 via the qcldwbchatbotcheckuser function. This can allow unauthenticated attackers to extract sensitive data including confirmation as to whether a user name exists on the site as well as order information for existing users.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-5254?
CVE-2023-5254 refers to a vulnerability in the ChatBot plugin for WordPress that allows unauthenticated attackers to extract sensitive data.
What is the severity of CVE-2023-5254?
CVE-2023-5254 has a severity rating of 5.3, which is considered medium.
How does CVE-2023-5254 affect the ChatBot plugin?
CVE-2023-5254 affects versions up to, and including, 4.8.9 of the ChatBot plugin for WordPress.
How can unauthenticated attackers exploit CVE-2023-5254?
Unauthenticated attackers can exploit CVE-2023-5254 by using the qcld_wb_chatbot_check_user function to extract sensitive data, including confirmation of user name existence on the site.
Is there a fix available for CVE-2023-5254?
Yes, upgrading to version 4.9.1 or higher of the ChatBot plugin for WordPress fixes CVE-2023-5254.