quantumcloud Vulnerabilities and Affected Products
Vulnerabilities associated with AI Infographic Maker.
Products
Clear product- WPBot – AI ChatBot for Live Support, Lead Generation, AI Services15 vulnerabilities
- Simple Link Directory11 vulnerabilities
- ChatBot8 vulnerabilities
- AI ChatBot5 vulnerabilities
- WPBot Pro Wordpress Chatbot5 vulnerabilities
- Conversational Forms for ChatBot4 vulnerabilities
- Simple Business Directory Pro4 vulnerabilities
- AI Infographic Maker2 vulnerabilities
- infographic_maker2 vulnerabilities
- KBx Pro Ultimate2 vulnerabilities
- SEO Help2 vulnerabilities
- Simple Link Directory Pro2 vulnerabilities
- ChatBot for eCommerce – WoowBot1 vulnerability
- ChatBot with AI1 vulnerability
- Floating Action Buttons1 vulnerability
- Floating Buttons for WooCommerce1 vulnerability
- floating_buttons1 vulnerability
- Highlight1 vulnerability
- iChart – Easy Charts and Graphs1 vulnerability
- Infographic Maker – iList1 vulnerability
- QC SEO Help for llms.txt, AI Analytics, AI Content Writer, Subtitle to Article1 vulnerability
- simple_link_directory1 vulnerability
- simple_video_directory1 vulnerability
- Slider Hero with Video Background, Animation1 vulnerability
- WoowBot Pro Max1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-12415MEDIUM | AI Infographic Maker <= 4.9.0 - Unauthenticated Arbitrary Shortcode ExecutionThe The AI Infographic Maker plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.9.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. CWE-94Jan 31, 2025 | CVSS6.5v3.1 | EPSS0.471% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5858MEDIUM | Infographic Maker iList <= 4.7.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Title UpdateThe AI Infographic Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the qcld_openai_title_generate_desc AJAX action in all versions up to, and including, 4.7.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary post titles. CWE-862Jun 15, 2024 | CVSS4.3v3.1 | EPSS0.323% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |