Data Modification Vulnerability in WPBot Pro Chatbot Plugin for WordPress
CVE-2024-12879
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 January 2025
What is CVE-2024-12879?
The WPBot Pro Chatbot plugin for WordPress is susceptible to unauthorized data modifications due to a missing capability check in the 'qc_wp_latest_update_check_pro' function. This flaw affects all versions up to and including 13.5.5, permitting authenticated attackers with at least Subscriber-level permissions to create arbitrary Simple Text Responses to chat queries, posing a risk of manipulation and misinformation.
Affected Version(s)
WPBot Pro Wordpress Chatbot * <= 13.5.5