CVE-2024-4560: Kognetiks Chatbot for WordPress <= 1.9.9 - Unauthenticated Arbitrary File Upload via chatbot_chatgpt_upload_file_to_assistant Function
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the chatbotchatgptuploadfiletoassistant function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers, with to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Kognetiks Chatbot for WordPressto a version that resolves this vulnerability.Fixed in 1.9.9
Event History
Frequently Asked Questions
What are the potential risks associated with CVE-2024-4560?
CVE-2024-4560 allows for arbitrary file uploads which can lead to unauthorized access, data breaches, or malware deployment.
How can I determine if my site is affected by CVE-2024-4560?
If you are using the Kognetiks Chatbot for WordPress plugin version 1.9.9 or earlier, your site is vulnerable to CVE-2024-4560.
What steps should I take to fix CVE-2024-4560?
To mitigate CVE-2024-4560, update the Kognetiks Chatbot for WordPress plugin to the latest version immediately.
Are there any workarounds for CVE-2024-4560 while waiting for an update?
Disabling the Kognetiks Chatbot for WordPress plugin until a patch is applied can serve as a temporary workaround for CVE-2024-4560.
Is there any indication of active exploitation for CVE-2024-4560?
Currently, there are no confirmed reports of active exploitation for CVE-2024-4560, but the vulnerability poses significant risk.