nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-13091 CVE-2024-13091
CRITICAL
WPBot Pro Wordpress Chatbot <= 13.5.4 - Unauthenticated Arbitrary File Upload
Record summary
CVE-2024-13091 has a selected CVSS score of 9.8 (critical).
Description
The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'qcld_wpcfb_file_upload' function in all versions up to, and including, 13.5.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The exploit requires thee ChatBot Conversational Forms plugin and the Conversational Form Builder Pro addon plugin.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 22, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WPBot Pro Wordpress ChatbotBrowse QuantumCloud / WPBot Pro Wordpress ChatbotDefault status: unaffected | CVE List | Through 13.5.4 | affected |
References
3wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/0f9b6979-2662-4d2f-9656-b880dd80832c?source=cve wpbot.pro
https://www.wpbot.pro/