cleantalk
Vulnerabilities and Security Researches

AI ChatBot, CVE-2023-1011

CVE, Research URL

CVE-2023-1011

Application

AI ChatBot

Published on
May 08, 2023
Research Description
The AI ChatBot WordPress plugin before 4.4.5 does not escape most of its settings before outputting them back in the dashboard, and does not have a proper CSRF check, allowing attackers to make a logged in admin set XSS payloads in them.
Affected versions
Min -, max 4.4.7.
Status
vulnerable