WPBot
cpe:2.3:a:quantumcloud:ai_chatbot:*:*:*:*:wordpress:*:*, +1 more
- <= 8.5.6
A vulnerability exists in the WPBot - AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress, in all versions up to and including 8.5.6. The issue stems from the plugin's failure to properly verify user authorization, allowing unauthenticated attackers to delete arbitrary chat session records from the wpbot_user and wpbot_conversation database tables. This deletion includes chat histories and conversation logs, which can be exploited by supplying a crafted userid value.
Exploitation of this vulnerability allows for the unauthorized deletion of chat session records and conversation histories from the affected WordPress site.
To reproduce this vulnerability, send a request to the WordPress site with an unverified userid parameter. This can be done through the admin-ajax.php endpoint, which the plugin uses to handle chat session data. The request can be made without authentication, and if the userid parameter is crafted correctly, it will trigger the deletion of the corresponding chat session records from the database.
Users are advised to update the WPBot - AI ChatBot for Live Support, Lead Generation, AI Services plugin to version 8.5.7 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.