Show filters
67 Total Results
Displaying 11-20 of 67
Sort by:
Attacker Value
Unknown
CVE-2024-10530
Disclosure Date: November 13, 2024 (last updated November 19, 2024)
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the add_new_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to create new GTP assistants.
0
Attacker Value
Unknown
CVE-2024-10529
Disclosure Date: November 13, 2024 (last updated November 19, 2024)
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete GTP assistants.
0
Attacker Value
Unknown
CVE-2024-6846
Disclosure Date: September 05, 2024 (last updated September 05, 2024)
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs
0
Attacker Value
Unknown
CVE-2024-6722
Disclosure Date: September 04, 2024 (last updated October 08, 2024)
The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2024-6847
Disclosure Date: August 20, 2024 (last updated August 20, 2024)
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.
0
Attacker Value
Unknown
CVE-2024-6843
Disclosure Date: August 19, 2024 (last updated August 19, 2024)
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not sanitise and escape user inputs, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins
0
Attacker Value
Unknown
CVE-2024-38791
Disclosure Date: August 01, 2024 (last updated August 02, 2024)
Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot allows Server Side Request Forgery.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.4.7.
0
Attacker Value
Unknown
CVE-2024-5969
Disclosure Date: July 27, 2024 (last updated January 05, 2025)
The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is due to insufficient limitations on the email recipient and the content in the 'aiomatic_send_email' function which are reachable via AJAX. This makes it possible for unauthenticated attackers to send emails with any content to any recipient.
0
Attacker Value
Unknown
CVE-2024-6669
Disclosure Date: July 17, 2024 (last updated July 20, 2024)
The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
0
Attacker Value
Unknown
CVE-2024-5993
Disclosure Date: July 09, 2024 (last updated January 05, 2025)
The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_session' function in all versions up to, and including, 3.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the session token of the chatbot.
0