Vulnerabilities (CVE)

Filtered by vendor Webdigit Subscribe
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-6843 1 Webdigit 1 Chatbot With Chatgpt 2025-05-27 N/A 6.1 MEDIUM
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not sanitise and escape user inputs, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins
CVE-2024-6847 1 Webdigit 1 Chatbot With Chatgpt 2025-05-27 N/A 9.8 CRITICAL
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.
CVE-2024-6846 1 Webdigit 1 Chatbot With Chatgpt 2025-05-16 N/A 5.3 MEDIUM
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs