The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in a function hooked to init, allowing unauthenticated users to update some settings, leading to Stored XSS due to the lack of escaping when outputting them in the admin dashboard
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/1a5cbcfc-fa55-433a-a76b-3881b6c4bea2 | Exploit |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: WPScan
Published: 2023-05-08T13:58:05.324Z
Updated: 2023-05-08T13:58:05.324Z
Reserved: 2023-03-27T14:29:14.721Z
Link: CVE-2023-1660
JSON object: View
NVD Information
Status : Modified
Published: 2023-05-08T14:15:13.173
Modified: 2023-11-07T04:04:31.473
Link: CVE-2023-1660
JSON object: View
Redhat Information
No data.
CWE
No CWE.