quantumcloud Vulnerabilities and Affected Products
Vulnerabilities associated with AI ChatBot.
Products
Clear product- WPBot – AI ChatBot for Live Support, Lead Generation, AI Services15 vulnerabilities
- Simple Link Directory11 vulnerabilities
- ChatBot8 vulnerabilities
- AI ChatBot5 vulnerabilities
- WPBot Pro Wordpress Chatbot5 vulnerabilities
- Conversational Forms for ChatBot4 vulnerabilities
- Simple Business Directory Pro4 vulnerabilities
- AI Infographic Maker2 vulnerabilities
- infographic_maker2 vulnerabilities
- KBx Pro Ultimate2 vulnerabilities
- SEO Help2 vulnerabilities
- Simple Link Directory Pro2 vulnerabilities
- ChatBot for eCommerce – WoowBot1 vulnerability
- ChatBot with AI1 vulnerability
- Floating Action Buttons1 vulnerability
- Floating Buttons for WooCommerce1 vulnerability
- floating_buttons1 vulnerability
- Highlight1 vulnerability
- iChart – Easy Charts and Graphs1 vulnerability
- Infographic Maker – iList1 vulnerability
- QC SEO Help for llms.txt, AI Analytics, AI Content Writer, Subtitle to Article1 vulnerability
- simple_link_directory1 vulnerability
- simple_video_directory1 vulnerability
- Slider Hero with Video Background, Animation1 vulnerability
- WoowBot Pro Max1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-48741HIGH | WordPress ChatBot Plugin <= 4.7.8 is vulnerable to SQL InjectionImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud AI ChatBot.This issue affects AI ChatBot: from n/a through 4.7.8. CWE-89Dec 19, 2023 | CVSS7.6v3.1 | EPSS0.725% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-5606MEDIUM | The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions 4.8.6 through 4.9.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. NOTE: This vu… CWE-79Nov 2, 2023 | CVSS4.4v3.1 | EPSS0.32% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-44993MEDIUM | WordPress ChatBot Plugin <= 4.7.8 is vulnerable to Cross Site Request Forgery (CSRF)Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.7.8 versions. CWE-352Oct 9, 2023 | CVSS4.3v3.1 | EPSS0.214% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-47613MEDIUM | WordPress AI ChatBot Plugin <= 4.3.0 is vulnerable to Cross Site Scripting (XSS)Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud AI ChatBot plugin <= 4.3.0 versions. CWE-79Mar 29, 2023 | CVSS5.9v3.1 | EPSS0.421% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-24415MEDIUM | WordPress AI ChatBot plugin <= 4.2.8 is vulnerable to Cross Site Request Forgery (CSRF)Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.2.8 versions. CWE-352Feb 23, 2023 | CVSS5.4v3.1 | EPSS0.264% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |