CVE-2024-6846

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:webdigit:chatbot_with_chatgpt:*:*:*:*:*:wordpress:*:*

History

16 May 2025, 20:21

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:webdigit:chatbot_with_chatgpt:*:*:*:*:*:wordpress:*:*
First Time Webdigit
Webdigit chatbot With Chatgpt
References () https://wpscan.com/vulnerability/d48fdab3-669c-4870-a2f9-6c39a7c25fd8/ - () https://wpscan.com/vulnerability/d48fdab3-669c-4870-a2f9-6c39a7c25fd8/ - Exploit, Third Party Advisory

05 Sep 2024, 14:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
Summary
  • (es) El Chatbot con el complemento ChatGPT de WordPress anterior a la versión 2.4.5 no valida el acceso en algunas rutas REST, lo que permite que un usuario no autenticado elimine los registros de errores y chats.

05 Sep 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-05 06:15

Updated : 2025-05-16 20:21


NVD link : CVE-2024-6846

Mitre link : CVE-2024-6846

CVE.ORG link : CVE-2024-6846


JSON object : View

Products Affected

webdigit

  • chatbot_with_chatgpt