The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks on the corresponding functions in versions up to, and including, 4.8.9 as well as 4.9.2. This makes it possible for unauthenticated attackers to perform some of those actions that were intended for higher privileged users.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Wordfence
Published: 2023-10-20T07:29:26.096Z
Updated: 2023-10-23T13:01:54.092Z
Reserved: 2023-10-11T19:00:32.298Z
Link: CVE-2023-5533
JSON object: View
NVD Information
Status : Modified
Published: 2023-10-20T08:15:13.450
Modified: 2023-11-07T04:24:07.453
Link: CVE-2023-5533
JSON object: View
Redhat Information
No data.
CWE