CVE-2023-5241

Publication date

2023-10-19 05:34:10

Family

Wordfence

State

PUBLISHED

Description

The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to append "