PT-2025-21775 · WordPress · Wpbot Pro
Published
2025-05-17
·
Updated
2025-05-22
·
CVE-2025-3812
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
WPBot Pro Wordpress Chatbot plugin versions up to, and including, 13.6.2
Description:
The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the
qcld openai delete training file() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted, such as wp-config.php.Recommendations:
For WPBot Pro Wordpress Chatbot plugin versions up to, and including, 13.6.2, update to a version that fixes the
qcld openai delete training file() function issue to prevent arbitrary file deletion.
As a temporary workaround, consider disabling the qcld openai delete training file() function until a patch is available to prevent exploitation.
Restrict access to the plugin's file deletion functionality to minimize the risk of exploitation.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpbot Pro