CVE-2023-5254

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/10/2023
Last modified:
12/05/2025

Description

The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9 via the qcld_wb_chatbot_check_user function. This can allow unauthenticated attackers to extract sensitive data including confirmation as to whether a user name exists on the site as well as order information for existing users.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:quantumcloud:wpbot:*:*:*:*:*:wordpress:*:* 4.9.1 (excluding)