PT-2025-43508 · WordPress · Mxchat – Ai Chatbot For Wordpress

Published

2025-10-23

·

Updated

2025-10-23

·

CVE-2025-10705

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions MxChat – AI Chatbot for WordPress plugin for WordPress versions up to and including 2.4.6
Description The software is susceptible to a Blind Server-Side Request Forgery due to inadequate validation of user-provided URLs within the PDF processing functionality. This allows unauthenticated attackers to compel the WordPress server to make HTTP requests to arbitrary destinations through the mxchat handle chat request AJAX action.
Recommendations Update to a version beyond 2.4.6.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10705

Affected Products

Mxchat – Ai Chatbot For Wordpress