Lucene search

K
wpvulndbWpvulndbWPVDB-ID:8FA2ECD1-31AC-47F8-A9D4-08F30710EB75
HistoryOct 24, 2023 - 12:00 a.m.

AI ChatBot < 4.9.1 - Missing authorization in AJAX calls

2023-10-2400:00:00
wpscan.com
3
chatbot
ajax
authorization
attackers
vulnerability

6.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.1%

Description The plugin does not check capabilities when processing AJAX actions, allowing unauthenticated attackers to perform actions intended for higher privileged users.

CPENameOperatorVersion
eq4.9.1

6.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.1%

Related for WPVDB-ID:8FA2ECD1-31AC-47F8-A9D4-08F30710EB75