Beveiligingsadvies

CVE-2023-1660

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-05-08 13:58:05
Laatst bijgewerkt 2025-05-05 16:06:29
Toegewezen door WPScan
CVSS-score 6.1
Status PUBLISHED

Beschrijving

The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in a function hooked to init, allowing unauthenticated users to update some settings, leading to Stored XSS due to the lack of escaping when outputting them in the admin dashboard