Record summary

CVE-2024-6846 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 5, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Chatbot with ChatGPT WordPress

Default status: unaffected

CVE ListBefore 2.4.5affected

Default status: unaffected

CVE ListBefore 2.4.5affected

Nuclei templates

1
ProjectDiscoveryMEDIUMSmartSearchWP <= 2.4.4 - Unauthenticated Log PurgeCVSS 5.3

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs.

Impact

Unauthenticated attackers can delete error and chat logs, potentially destroying evidence of attacks or system issues.

Remediation

Update SmartSearchWP plugin to version 2.4.5 or later to address the unauthorized log purge vulnerability.

Authorss4e-io
Template tagswpscancvecve2024wpwordpresswp-pluginsmartsearchwpchatgptvulnai
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
FOFA: body="/wp-content/plugins/smartsearchwp"

Source: ProjectDiscovery

References

2