Lucene search

K
wpvulndbWpvulndbWPVDB-ID:3EA9A271-CA02-484C-BC59-E650E03DB601
HistoryOct 24, 2023 - 12:00 a.m.

AI ChatBot < 4.9.3 - Missing authorization in AJAX calls

2023-10-2400:00:00
wpscan.com
2
chatbot
4.9.3
missing authorization
ajax
cve-2023-5533
reintroduced
version 4.9.2

9.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.1%

Description The plugin does not check capabilities when processing AJAX actions, allowing unauthenticated attackers to perform actions intended for higher privileged users. This vulnerability is the same as CVE-2023-5533 but was reintroduced in version 4.9.2.

CPENameOperatorVersion
eq4.9.3

9.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.1%

Related for WPVDB-ID:3EA9A271-CA02-484C-BC59-E650E03DB601