Lucene search

K
wpvulndbWpvulndbWPVDB-ID:9972E172-0052-469C-BAC7-4DD4BAB144F7
HistoryOct 24, 2023 - 12:00 a.m.

AI ChatBot < 4.9.3 - Cross-Site Request Forgery (CSRF)

2023-10-2400:00:00
wpscan.com
10
chatbot
csrf
vulnerability
version 4.9.2

EPSS

0.001

Percentile

20.5%

Description The plugin does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to perform actions on their behalf by tricking a logged in user to submit a crafted request. This vulnerability is the same as CVE-2023-5534, but was reintroduced in version 4.9.2.

EPSS

0.001

Percentile

20.5%

Related for WPVDB-ID:9972E172-0052-469C-BAC7-4DD4BAB144F7