cleantalk
Vulnerabilities and Security Researches

AI ChatBot, CVE-2023-1660

CVE, Research URL

CVE-2023-1660

Application

AI ChatBot

Published on
May 08, 2023
Research Description
The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in a function hooked to init, allowing unauthenticated users to update some settings, leading to Stored XSS due to the lack of escaping when outputting them in the admin dashboard
Affected versions
Min -, max 4.4.9.
Status
vulnerable