9.8

CVE-2023-5533

AI ChatBot <= 4.8.9 and 4.9.2 - Missing Authorization on AJAX actions

AI ChatBot <= 4.8.9 and 4.9.2 - Missing Authorization on AJAX actions

The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks on the corresponding functions in versions up to, and including, 4.8.9 as well as 4.9.2. This makes it possible for unauthenticated attackers to perform some of those actions that were intended for higher privileged users.
Mögliche Gegenmaßnahme
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services: Update to one of the following versions, or a newer patched version: 4.9.1, 4.9.3
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QuantumcloudWpbot SwPlatformwordpress Version <= 4.8.9
QuantumcloudWpbot Version4.9.2 SwPlatformwordpress
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt WPBot – AI ChatBot for Live Support, Lead Generation, AI Services
Version *-4.8.9
Version 4.9.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.405
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
security@wordfence.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=2977505%40chatbot%2Ftrunk&old=2967435%40chatbot%2Ftrunk&sfp_email=&sfph_mail=
Patch
https://www.wordfence.com/threat-intel/vulnerabilities/id/a9db002f-ff41-493a-87b1-5f0b4b07cfc2?source=cve
Third Party Advisory
Product
https://www.wordfence.com/threat-intel/vulnerabilities/id/a9db002f-ff41-493a-87b1-5f0b4b07cfc2
Third Party Advisory