CVE-2023-2811

Severity
4.8MEDIUM
EPSS
0.1%
top 68.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 19

Description

The AI ChatBot WordPress plugin before 4.5.6 does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks to all admin when setting chatbot and all client when using chatbot

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages2 packages

CVEListV5unknown/ai_chatbot< 4.5.6
NVDquantumcloud/wpbot< 4.5.6

🔴Vulnerability Details

2
GHSA
GHSA-44c7-92p2-r6w4: The AI ChatBot WordPress plugin before 42023-06-19
CVEList
AI ChatBot < 4.5.6 - Admin+ Stored Cross-Site Scripting2023-06-19
CVE-2023-2811 (MEDIUM CVSS 4.8) | The AI ChatBot WordPress plugin bef | cvebase.io