CVE-2024-12879: WPBot Pro Wordpress Chatbot <= 13.5.5 - Missing Authorization to Authenticated (Subscriber+) Simple Text Response Creation
The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'qcwplatestupdatecheckpro' function in all versions up to, and including, 13.5.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create Simple Text Responses to chat queries.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12879?
The severity of CVE-2024-12879 is classified as medium due to the potential for unauthorized data modification.
How do I fix CVE-2024-12879?
To fix CVE-2024-12879, update the WPBot Pro plugin to version 13.5.6 or later.
Who is affected by CVE-2024-12879?
CVE-2024-12879 affects all versions of the WPBot Pro plugin for WordPress up to and including version 13.5.5.
What type of attack does CVE-2024-12879 allow?
CVE-2024-12879 allows authenticated attackers to modify data without proper authorization.
Is there a workaround for CVE-2024-12879?
Currently, there are no known workarounds for CVE-2024-12879 other than upgrading to the patched version.