PT-2025-21775 · WordPress · Wpbot Pro

Published

2025-05-17

·

Updated

2025-05-22

·

CVE-2025-3812

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: WPBot Pro Wordpress Chatbot plugin versions up to, and including, 13.6.2
Description: The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the qcld openai delete training file() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted, such as wp-config.php.
Recommendations: For WPBot Pro Wordpress Chatbot plugin versions up to, and including, 13.6.2, update to a version that fixes the qcld openai delete training file() function issue to prevent arbitrary file deletion. As a temporary workaround, consider disabling the qcld openai delete training file() function until a patch is available to prevent exploitation. Restrict access to the plugin's file deletion functionality to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-3812

Affected Products

Wpbot Pro