5.3
CVE-2024-6846
- EPSS 1.25%
- Veröffentlicht 05.09.2024 06:15:03
- Zuletzt bearbeitet 16.05.2025 20:21:42
- Erkennungen
SmartSearchWP <= 2.4.4 - Unauthenticated Log Purge
Chatbot with ChatGPT <= 2.4.4 - Missing Authorization
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs
Mögliche Gegenmaßnahme
AI Chatbot & Semantic Search: ChatGPT Answers From Your Content: Update to version 2.4.5, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Webdigit ≫ Chatbot With Chatgpt SwPlatform wordpress Version < 2.4.5
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
AI Chatbot & Semantic Search: ChatGPT Answers From Your Content
Version
*-2.4.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.25% | 0.666 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
https://wpscan.com/vulnerability/d48fdab3-669c-4870-a2f9-6c39a7c25fd8/
https://www.wordfence.com/threat-intel/vulnerabilities/id/17b0366c-f170-420d-b0d5-5c2f9f9e1cca