Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-5254
HistoryOct 19, 2023 - 6:15 a.m.

Code injection

2023-10-1906:15:00
PRIOn knowledge base
www.prio-n.com
2
code injection
sensitive information exposure
unauthenticated attackers
order information

6.1 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.7%

The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9 via the qcld_wb_chatbot_check_user function. This can allow unauthenticated attackers to extract sensitive data including confirmation as to whether a user name exists on the site as well as order information for existing users.

CPENameOperatorVersion
ai_chatbotlt4.9.1

6.1 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.7%

Related for PRION:CVE-2023-5254