PT-2024-37901 · WordPress · Chatbot With Chatgpt

Karolis Narvilas

·

Published

2024-08-19

·

Updated

2025-05-27

·

CVE-2024-6847

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Chatbot with ChatGPT WordPress plugin versions prior to 2.4.5
Description The issue is related to a SQL injection vulnerability. It occurs because the plugin does not properly sanitise and escape a parameter before using it in a SQL statement. This vulnerability is exploitable by unauthenticated users when submitting messages to the chatbot.
Recommendations For versions prior to 2.4.5, update to version 2.4.5 or later to prevent exploitation by unauthenticated users when submitting messages to the chatbot. As a temporary workaround, consider restricting access to the chatbot functionality until the update is applied.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-6847

Affected Products

Chatbot With Chatgpt