CVE-2025-11256: Kognetiks Chatbot <= 2.3.5 - Missing Authorization to Unauthenticated Limited File Uploads and Conversation Erasing
The Kognetiks Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.3.5. This makes it possible for unauthenticated attackers to upload limited safe files and erase conversations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11256?
CVE-2025-11256 is classified as a critical vulnerability due to its potential for unauthorized data modification.
How do I fix CVE-2025-11256?
To mitigate CVE-2025-11256, update the Kognetiks Chatbot plugin to version 2.3.6 or later, which includes necessary capability checks.
What are the risks associated with CVE-2025-11256?
The risks associated with CVE-2025-11256 include the possibility of unauthenticated attackers altering data and uploading malicious files.
Which versions of Kognetiks Chatbot are affected by CVE-2025-11256?
All versions of Kognetiks Chatbot up to and including 2.3.5 are affected by CVE-2025-11256.
Who can exploit CVE-2025-11256?
CVE-2025-11256 can be exploited by unauthenticated attackers, making it accessible to anyone without the need for a legitimate account.