cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forchatbot-chatgpt chatbot-chatgpt

Direction: descending
Nov 14, 2024

Kognetiks Chatbot for WordPress # CVE-2024-10530

CVE, Research URL

CVE-2024-10530

Date
Nov 13, 2024
Research Description
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the add_new_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to create new GTP assistants.
Affected versions
Min -, max -.
Status
vulnerable

Kognetiks Chatbot for WordPress # CVE-2024-10531

CVE, Research URL

CVE-2024-10531

Date
Nov 13, 2024
Research Description
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to update GTP assistants.
Affected versions
Min -, max -.
Status
vulnerable

Kognetiks Chatbot for WordPress # CVE-2024-10684

CVE, Research URL

CVE-2024-10684

Date
Nov 13, 2024
Research Description
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' parameter in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable

Kognetiks Chatbot for WordPress # CVE-2024-10529

CVE, Research URL

CVE-2024-10529

Date
Nov 13, 2024
Research Description
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete GTP assistants.
Affected versions
Min -, max -.
Status
vulnerable

Kognetiks Chatbot for WordPress # CVE-2024-11143

CVE, Research URL

CVE-2024-11143

Date
Nov 13, 2024
Research Description
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.8. This is due to missing or incorrect nonce validation on the update_assistant, add_new_assistant, and delete_assistant functions. This makes it possible for unauthenticated attackers to modify assistants via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable
Jun 10, 2024

Kognetiks Chatbot for WordPress # CVE-2024-35738

CVE, Research URL

CVE-2024-35738

Date
Jun 08, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kognetiks Kognetiks Chatbot for WordPress allows Stored XSS.This issue affects Kognetiks Chatbot for WordPress: from n/a through 1.9.8.
Affected versions
Min -, max -.
Status
vulnerable
Jun 07, 2024

Kognetiks Chatbot for WordPress # CVE-2024-4560

CVE, Research URL

CVE-2024-4560

Date
May 14, 2024
Research Description
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the chatbot_chatgpt_upload_file_to_assistant function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers, with to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected versions
Min -, max -.
Status
vulnerable

Kognetiks Chatbot for WordPress # CVE-2024-32700

CVE, Research URL

CVE-2024-32700

Date
May 14, 2024
Research Description
Unrestricted Upload of File with Dangerous Type vulnerability in Kognetiks Kognetiks Chatbot for WordPress.This issue affects Kognetiks Chatbot for WordPress: from n/a through 2.0.0.
Affected versions
Min -, max -.
Status
vulnerable