First published: Thu Jan 09 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ChatBot for WordPress - WPBot Conversational Forms for ChatBot allows Stored XSS.This issue affects Conversational Forms for ChatBot: from n/a through 1.4.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPBot Conversational Forms by QuantumCloud | <=1.4.2 |
Update the WordPress Conversational Forms for ChatBot wordpress plugin to the latest available version (at least 1.4.3).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-22813 is classified as a Cross-site Scripting (XSS) vulnerability affecting versions up to 1.4.2 of Conversational Forms for ChatBot.
To fix CVE-2025-22813, update the Conversational Forms for ChatBot to the latest version that addresses this vulnerability.
CVE-2025-22813 affects the ChatBot for WordPress - WPBot Conversational Forms plugin, specifically versions from n/a through 1.4.2.
Yes, CVE-2025-22813 is a stored Cross-site Scripting vulnerability that allows attackers to inject malicious scripts.
The vendor for the vulnerable software in CVE-2025-22813 is WordPress, specifically for the plugin WPBot Conversational Forms.