quantumcloud Vulnerabilities and Affected Products
Vulnerabilities associated with QC SEO Help for llms.txt, AI Analytics, AI Content Writer, Subtitle to Article.
Products
Clear product- WPBot – AI ChatBot for Live Support, Lead Generation, AI Services15 vulnerabilities
- Simple Link Directory11 vulnerabilities
- ChatBot8 vulnerabilities
- AI ChatBot5 vulnerabilities
- WPBot Pro Wordpress Chatbot5 vulnerabilities
- Conversational Forms for ChatBot4 vulnerabilities
- Simple Business Directory Pro4 vulnerabilities
- AI Infographic Maker2 vulnerabilities
- infographic_maker2 vulnerabilities
- KBx Pro Ultimate2 vulnerabilities
- SEO Help2 vulnerabilities
- Simple Link Directory Pro2 vulnerabilities
- ChatBot for eCommerce – WoowBot1 vulnerability
- ChatBot with AI1 vulnerability
- Floating Action Buttons1 vulnerability
- Floating Buttons for WooCommerce1 vulnerability
- floating_buttons1 vulnerability
- Highlight1 vulnerability
- iChart – Easy Charts and Graphs1 vulnerability
- Infographic Maker – iList1 vulnerability
- QC SEO Help for llms.txt, AI Analytics, AI Content Writer, Subtitle to Article1 vulnerability
- simple_link_directory1 vulnerability
- simple_video_directory1 vulnerability
- Slider Hero with Video Background, Animation1 vulnerability
- WoowBot Pro Max1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-12156MEDIUM | AI Content Writer, RSS Feed to Post, Autoblogging SEO Help <= 6.1.3 - Reflected Cross-Site ScriptingThe AI Content Writer, RSS Feed to Post, Autoblogging SEO Help plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 6.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CWE-79Dec 12, 2024 | CVSS6.1v3.1 | EPSS0.397% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |