First published: Thu Nov 02 2023(Updated: )
The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions 4.8.6 through 4.9.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. NOTE: This vulnerability is a re-introduction of CVE-2023-4253.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
>=4.8.6<4.9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2023-5606.
The severity level of CVE-2023-5606 is medium with a severity value of 4.4.
The vulnerability affects the ChatBot for WordPress versions 4.8.6 through 4.9.6.
The vulnerability is caused by insufficient input sanitization and output escaping in the FAQ Builder of the ChatBot for WordPress.
The vulnerability can be exploited by authenticated attackers with administrator-level permissions and above.