Unauthorized Modification of Data Vulnerability in AI ChatBot Plugin for WordPress
CVE-2024-0453
7.7HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 22 May 2024
What is CVE-2024-0453?
The AI ChatBot Plugin for WordPress is susceptible to unauthorized data modification due to a missing capability check within the openai_file_delete_callback function. This vulnerability affects all versions of the plugin up to and including 5.3.4, enabling authenticated attackers with subscriber-level access and higher to delete files from associated OpenAI accounts. Users should take immediate action to mitigate this risk and protect their data.
Affected Version(s)
AI ChatBot for WordPress – WPBot * <= 5.3.4