Filtered by vendor Quantumcloud Subscriptions
Filtered by product Ai Chatbot Subscriptions
Total 22 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-1651 1 Quantumcloud 1 Ai Chatbot 2024-11-21 5.4 Medium
The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in the AJAX action responsible to update the OpenAI settings, allowing any authenticated users, such as subscriber to update them. Furthermore, due to the lack of escaping of the settings, this could also lead to Stored XSS
CVE-2023-1011 1 Quantumcloud 1 Ai Chatbot 2024-11-21 6.1 Medium
The AI ChatBot WordPress plugin before 4.4.5 does not escape most of its settings before outputting them back in the dashboard, and does not have a proper CSRF check, allowing attackers to make a logged in admin set XSS payloads in them.