CVE-2023-5646: Path Traversal

Published Oct 20, 2023
·
Updated

Rejected reason: REJECT DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-5241. Reason: This record is a reservation duplicate of CVE-2023-5241. Notes: All CVE users should reference CVE-2023-5241 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

Other sources

The AI ChatBot for WordPress is vulnerable to Directory Traversal in version 4.9.2 via the qcldopenaiuploadpagetrainingfile function. This allows subscriber-level attackers to append "<?php" to any existing file on the server resulting in potential DoS when appended to critical files such as wp-config.php. This vulnerability is the same as CVE-2023-5241, but was reintroduced in version 4.9.2.

Affected Software

1 affected component
AI ChatBot WordPress Plugin=4.9.2

Event History

Oct 20, 2023
CVE Published
via MITRE·01:51 AM
Rejected
via MITRE·01:51 AM
Data Sourced
02:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
Description
Jan 23, 2024
Rejected
via MITRE·10:28 PM
Rejected
via NVD·11:15 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What should I do regarding CVE-2023-5646?

You should ignore CVE-2023-5646 and refer to CVE-2023-5241 for relevant information.

2

Is CVE-2023-5646 a significant vulnerability?

CVE-2023-5646 has been marked as a duplicate and is not meant to be used.

3

What software is affected by CVE-2023-5646?

CVE-2023-5646 pertains to the AI ChatBot WordPress Plugin version 4.9.2.

4

Can I obtain more details on CVE-2023-5646?

Since CVE-2023-5646 is a rejected record, all inquiries should be directed to CVE-2023-5241 for detailed information.

5

How do I ensure I am protected against the issues related to CVE-2023-5646?

To mitigate risks associated with CVE-2023-5646, always refer to and apply the patches or recommendations provided for CVE-2023-5241.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203