PT-2023-31969 · WordPress · The Ai Chatbot For Wordpress

Marco Wotschka

·

Published

2023-10-18

·

Updated

2023-12-22

·

CVE-2023-5241

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions The AI ChatBot for WordPress versions up to, and including, 4.8.9 The AI ChatBot for WordPress version 4.9.2
Description The issue allows subscriber-level attackers to perform Directory Traversal, potentially leading to a Denial of Service (DoS) when appended to critical files. This is achieved by appending "<?php" to any existing file on the server via the qcld openai upload pagetraining file function.
Recommendations For versions up to, and including, 4.8.9, consider disabling the qcld openai upload pagetraining file function until a patch is available. For version 4.9.2, consider disabling the qcld openai upload pagetraining file function until a patch is available. As a temporary workaround, restrict access to critical files such as wp-config.php to minimize the risk of exploitation.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-5241

Affected Products

The Ai Chatbot For Wordpress