PT-2024-16345 · Kognetiks · Kognetiks Chatbot For Wordpress

Tieu Pham Trong Nhan

·

Published

2024-11-12

·

Updated

2024-11-18

·

CVE-2024-10529

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kognetiks Chatbot for WordPress plugin versions up to, and including, 2.1.7
Description The Kognetiks Chatbot for WordPress plugin is vulnerable to unauthorized modification of data due to a missing capability check on the delete assistant() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete GTP assistants.
Recommendations For versions up to, and including, 2.1.7, update to the latest version to mitigate risks. As a temporary workaround, consider disabling the delete assistant() function until a patch is available. Restrict access to the plugin to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-10529

Affected Products

Kognetiks Chatbot For Wordpress