Lucene search

K
cvelistWPScanCVELIST:CVE-2023-1650
HistoryMay 08, 2023 - 1:58 p.m.

CVE-2023-1650 ChatBot < 4.4.7 - Unauthenticated PHP Object Injection

2023-05-0813:58:12
WPScan
www.cve.org
1
cve-2023-1650
unauthenticated
object injection
ajax
wordpress

9.9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

60.0%

The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Object Injection when a suitable gadget is present on the blog

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "AI ChatBot",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThan": "4.4.7"
      }
    ],
    "defaultStatus": "unaffected",
    "collectionURL": "https://wordpress.org/plugins"
  }
]

9.9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

60.0%

Related for CVELIST:CVE-2023-1650