CVE-2025-11256
- EPSS 0.13%
- Veröffentlicht 18.10.2025 07:26:31
- Zuletzt bearbeitet 21.10.2025 19:31:25
The Kognetiks Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.3.5. This makes it possible for unauthenticated attackers to ...
CVE-2024-11143
- EPSS 0.09%
- Veröffentlicht 13.11.2024 03:15:05
- Zuletzt bearbeitet 18.11.2024 15:03:56
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.8. This is due to missing or incorrect nonce validation on the update_assistant, add_new_assistant, and del...
CVE-2024-10531
- EPSS 0.23%
- Veröffentlicht 13.11.2024 03:15:04
- Zuletzt bearbeitet 18.11.2024 15:02:30
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for a...
CVE-2024-10684
- EPSS 3.12%
- Veröffentlicht 13.11.2024 03:15:04
- Zuletzt bearbeitet 18.11.2024 15:03:08
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' parameter in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping. This makes it pos...
CVE-2024-10529
- EPSS 0.28%
- Veröffentlicht 13.11.2024 03:15:03
- Zuletzt bearbeitet 18.11.2024 14:59:15
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for a...
CVE-2024-10530
- EPSS 0.24%
- Veröffentlicht 13.11.2024 03:15:03
- Zuletzt bearbeitet 18.11.2024 14:59:30
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the add_new_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for ...
CVE-2024-4560
- EPSS 17.89%
- Veröffentlicht 14.05.2024 15:44:04
- Zuletzt bearbeitet 21.11.2024 09:43:06
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the chatbot_chatgpt_upload_file_to_assistant function in all versions up to, and including, 1.9.9. This makes it p...
- EPSS 61.69%
- Veröffentlicht 14.05.2024 15:36:58
- Zuletzt bearbeitet 21.11.2024 09:15:30
Unrestricted Upload of File with Dangerous Type vulnerability in Kognetiks Kognetiks Chatbot for WordPress.This issue affects Kognetiks Chatbot for WordPress: from n/a through 2.0.0.