PT-2024-37899 · WordPress · Chatbot With Chatgpt

Kieran Burge

·

Published

2024-09-24

·

Updated

2026-01-20

·

CVE-2024-6845

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Chatbot with ChatGPT WordPress plugin versions prior to 2.4.6
Description The issue is related to a lack of proper authorization in one of the plugin's REST endpoints, allowing unauthenticated users to retrieve an encoded key, which can then be decoded, resulting in the leak of the OpenAI API key.
Recommendations For versions prior to 2.4.6, update to version 2.4.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable REST endpoint until a patch is applied. Avoid using the affected plugin until the issue is resolved.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6845

Affected Products

Chatbot With Chatgpt