CVE-2024-10530: Kognetiks Chatbot for WordPress <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Assistant Addition
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the addnewassistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to create new GTP assistants.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10530?
CVE-2024-10530 has a moderate severity rating due to the potential for unauthorized data modification.
How do I fix CVE-2024-10530?
To fix CVE-2024-10530, update the Kognetiks Chatbot for WordPress plugin to version 2.1.8 or later.
Who is affected by CVE-2024-10530?
CVE-2024-10530 affects users of the Kognetiks Chatbot for WordPress plugin versions up to and including 2.1.7.
What type of attack is possible with CVE-2024-10530?
CVE-2024-10530 allows authenticated attackers to modify data due to a missing capability check.
When was CVE-2024-10530 discovered?
CVE-2024-10530 was publicly disclosed in the year 2024.