📦 Wpbot

by Quantumcloud

🔍 What is Wpbot?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-5241

CRITICAL CVSS 9.6 Oct 19, 2023

This vulnerability in the AI ChatBot for WordPress plugin allows attackers with subscriber-level access to perform directory traversal and append PHP code to any existing file on the server. This can ...

CVE-2023-5204

CRITICAL CVSS 9.8 Oct 19, 2023

This SQL injection vulnerability in the WordPress ChatBot plugin allows unauthenticated attackers to execute arbitrary SQL queries through the $strid parameter. Attackers can extract sensitive databas...

CVE-2023-1650

CRITICAL CVSS 9.8 May 8, 2023

This vulnerability in the AI ChatBot WordPress plugin allows unauthenticated attackers to perform PHP Object Injection by sending specially crafted cookies to an AJAX endpoint. This could lead to remo...

CVE-2024-22309

HIGH CVSS 8.7 Jan 24, 2024

This vulnerability allows unauthenticated attackers to perform PHP object injection via deserialization of untrusted data in the QuantumCloud ChatBot with AI WordPress plugin. It affects all WordPress...

CVE-2025-0329

MEDIUM CVSS 4.8 May 15, 2025

This vulnerability allows high-privilege WordPress users (like administrators) to inject malicious scripts into the AI ChatBot plugin settings, which then execute in other users' browsers. It affects ...

CVE-2024-6669

MEDIUM CVSS 5.5 Jul 17, 2024

This vulnerability allows authenticated attackers with administrator-level permissions to inject malicious scripts into WordPress admin settings via the WPBot plugin, which execute when users view aff...

CVE-2024-0451

MEDIUM CVSS 5.0 May 22, 2024

The AI ChatBot WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level access or higher to list files from a linked OpenAI account. This occurs becaus...

CVE-2024-0453

MEDIUM CVSS 5.0 May 22, 2024

The AI ChatBot WordPress plugin has an authorization vulnerability that allows authenticated users with subscriber-level access or higher to delete files from a linked OpenAI account. This occurs beca...

CVE-2022-47613

MEDIUM CVSS 5.9 Mar 29, 2023

This vulnerability allows authenticated administrators to inject malicious scripts into the QuantumCloud AI ChatBot WordPress plugin. When other users view the affected pages, these scripts execute in...