QuantumCloud WPBot Pro
cpe:2.3:a:quantumcloud:ai_chatbot:*:*:*:*:wordpress:*:*, +1 more
- <= 13.5.5
A vulnerability exists in the WPBot Pro WordPress Chatbot plugin, all versions through 13.5.5, due to a lack of proper capability checks in the 'qc_wp_latest_update_check_pro' function. This flaw allows authenticated attackers with Subscriber-level access or higher to create Simple Text Responses for chat queries, leading to unauthorized data modification.
Exploitation of this vulnerability allows for unauthorized creation of Simple Text Responses in the chatbot, potentially leading to misinformation or manipulation of chatbot interactions.
Users can update to WPBot Pro version 13.5.6 or a newer patched version to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.