First published: Fri Sep 13 2024(Updated: )
The AI Engine WordPress plugin before 2.4.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when viewing chatbot discussions.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jordy Meow AI Engine: ChatGPT Chatbot | <2.4.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6723 is a critical vulnerability that allows SQL injection due to improper sanitization in the AI Engine WordPress plugin.
To fix CVE-2024-6723, upgrade the AI Engine WordPress plugin to version 2.4.8 or later.
Admin users of the AI Engine WordPress plugin versions prior to 2.4.8 are at risk of CVE-2024-6723.
CVE-2024-6723 is classified as a SQL injection vulnerability.
CVE-2024-6723 is exploitable by admin users when viewing chatbot discussions within the WordPress dashboard.