CVE-2023-5241

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
19/10/2023
Last modified:
12/05/2025

Description

The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to append "

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:quantumcloud:wpbot:*:*:*:*:*:wordpress:*:* 4.9.1 (excluding)
cpe:2.3:a:quantumcloud:wpbot:4.9.2:*:*:*:*:wordpress:*:*