Lucene search

K
wpvulndbWpvulndbWPVDB-ID:B8341A4D-4473-41F6-9819-D06E0F78DA41
HistoryNov 23, 2023 - 12:00 a.m.

AI ChatBot < 4.9.1 and 4.9.2 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_file

2023-11-2300:00:00
wpscan.com
12
ai chatbot
wordpress
directory traversal
file write
vulnerability
version 4.9.2
qcld_openai_upload_pagetraining_file
subscriber-level attackers

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

52.0%

Description The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to append "

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

52.0%

Related for WPVDB-ID:B8341A4D-4473-41F6-9819-D06E0F78DA41