QuantumCloud WPBot Pro
cpe:2.3:a:quantumcloud:ai_chatbot:*:*:*:*:wordpress:*:*, +1 more
- <= 13.5.4
A vulnerability allowing arbitrary file uploads has been identified in the WPBot Pro WordPress Chatbot plugin, affecting all versions through 13.5.4. The issue arises from inadequate file type validation in the 'qcld_wpcfb_file_upload' function, enabling unauthenticated attackers to upload arbitrary files to the server. This vulnerability could potentially lead to remote code execution. Exploitation requires the ChatBot Conversational Forms plugin and the Conversational Form Builder Pro addon plugin.
The vulnerability allows for arbitrary file uploads, which could be exploited to execute malicious files on the server, potentially leading to remote code execution.
Users are advised to update the WPBot Pro WordPress Chatbot plugin to version 13.5.6 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.