CVE-2024-6846
SmartSearchWP <= 2.4.4 - Unauthenticated Log Purge
Record summary
CVE-2024-6846 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 5, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Chatbot with ChatGPT WordPressDefault status: unaffected | CVE List | Before 2.4.5 | affected |
chatbot_with_chatgpt_wordpressBrowse smartsearchwp / chatbot_with_chatgpt_wordpressDefault status: unaffected | CVE List | Before 2.4.5 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMSmartSearchWP <= 2.4.4 - Unauthenticated Log PurgeCVSS 5.3
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs.
Impact
Unauthenticated attackers can delete error and chat logs, potentially destroying evidence of attacks or system issues.
Remediation
Update SmartSearchWP plugin to version 2.4.5 or later to address the unauthorized log purge vulnerability.
Source: ProjectDiscovery