Show filters
67 Total Results
Displaying 11-20 of 67
Sort by:
Attacker Value
Unknown

CVE-2024-10530

Disclosure Date: November 13, 2024 (last updated November 19, 2024)
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the add_new_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to create new GTP assistants.
Attacker Value
Unknown

CVE-2024-10529

Disclosure Date: November 13, 2024 (last updated November 19, 2024)
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete GTP assistants.
Attacker Value
Unknown

CVE-2024-6846

Disclosure Date: September 05, 2024 (last updated September 05, 2024)
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs
0
Attacker Value
Unknown

CVE-2024-6722

Disclosure Date: September 04, 2024 (last updated October 08, 2024)
The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Attacker Value
Unknown

CVE-2024-6847

Disclosure Date: August 20, 2024 (last updated August 20, 2024)
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.
0
Attacker Value
Unknown

CVE-2024-6843

Disclosure Date: August 19, 2024 (last updated August 19, 2024)
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not sanitise and escape user inputs, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins
0
Attacker Value
Unknown

CVE-2024-38791

Disclosure Date: August 01, 2024 (last updated August 02, 2024)
Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot allows Server Side Request Forgery.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.4.7.
0
Attacker Value
Unknown

CVE-2024-5969

Disclosure Date: July 27, 2024 (last updated January 05, 2025)
The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is due to insufficient limitations on the email recipient and the content in the 'aiomatic_send_email' function which are reachable via AJAX. This makes it possible for unauthenticated attackers to send emails with any content to any recipient.
0
Attacker Value
Unknown

CVE-2024-6669

Disclosure Date: July 17, 2024 (last updated July 20, 2024)
The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Attacker Value
Unknown

CVE-2024-5993

Disclosure Date: July 09, 2024 (last updated January 05, 2025)
The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_session' function in all versions up to, and including, 3.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the session token of the chatbot.
0