VendorsQuantumCloudwpbotany version
Vulnerabilities

QuantumCloud WPBot any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

27CVEs
CVE-2023-1650
ChatBot < 4.4.7 - Unauthenticated PHP Object Injection
Published 2023-05-08 · Modified
9.8EPSS 0.344
CVE-2023-5204
AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_response
Published 2023-10-19 · Modified
9.8EPSS 0.068
CVE-2023-5533
AI ChatBot <= 4.8.9 and 4.9.2 - Missing Authorization on AJAX actions
Published 2023-10-20 · Modified
9.8EPSS 0.005
CVE-2024-22309
WordPress ChatBot Plugin <= 5.1.0 is vulnerable to PHP Object Injection
Published 2024-01-24 · Modified
9.8EPSS 0.005
CVE-2023-5241
AI ChatBot <= 4.8.9 and 4.9.2 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_file
Published 2023-10-19 · Modified
9.6EPSS 0.021
CVE-2023-5212
AI ChatBot <= 4.8.9 and 4.9.2- Authenticated (Subscriber+) Arbitrary File Deletion via qcld_openai_delete_training_file
Published 2023-10-19 · Modified
9.6EPSS 0.016
CVE-2023-44993
WordPress ChatBot Plugin <= 4.7.8 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-10-09 · Modified
8.8EPSS 0.002
CVE-2024-0453
AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_delete_callback
Published 2024-05-22 · Modified
7.7EPSS 0.004
CVE-2024-0452
AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_upload_callback
Published 2024-05-22 · Modified
7.7EPSS 0.004
CVE-2023-48741
WordPress ChatBot Plugin <= 4.7.8 is vulnerable to SQL Injection
Published 2023-12-19 · Modified
7.6EPSS 0.007
CVE-2023-1660
ChatBot < 4.4.9 - Unauthenticated Stored XSS
Published 2023-05-08 · Modified
6.1EPSS 0.003
CVE-2023-1011
ChatBot < 4.4.5 - Stored XSS via CSRF
Published 2023-05-08 · Modified
6.1EPSS 0.002
CVE-2022-47613
WordPress AI ChatBot Plugin <= 4.3.0 is vulnerable to Cross Site Scripting (XSS)
Published 2023-03-29 · Modified
5.9EPSS 0.004
CVE-2024-6669
AI ChatBot for WordPress – WPBot <= 5.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
Published 2024-07-17 · Modified
5.5EPSS 0.003
CVE-2023-1651
ChatBot < 4.4.9 - Subscriber+ OpenAI Settings Update to Stored XSS
Published 2023-05-08 · Modified
5.4EPSS 0.002
CVE-2023-5534
AI ChatBot <= 4.8.9 and 4.9.2 - Cross-Site Request Forgery on AJAX actions
Published 2023-10-20 · Modified
5.4EPSS 0.002
CVE-2023-5254
AI ChatBot <= 4.8.9 - Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_user
Published 2023-10-19 · Modified
5.3EPSS 0.008
CVE-2024-0451
AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_list_callback
Published 2024-05-22 · Modified
5.0EPSS 0.004
CVE-2023-3175
AI ChatBot < 4.6.1 - Admin+ Stored Cross-Site Scripting
Published 2023-07-10 · Modified
4.8EPSS 0.006
CVE-2023-4253
Chatbot < 4.7.8 - Admin+ Stored XSS in FAQ Builder
Published 2023-09-04 · Modified
4.8EPSS 0.005
CVE-2023-4254
Chatbot < 4.7.8 - Admin+ Stored XSS in Language Settings
Published 2023-09-04 · Modified
4.8EPSS 0.005
CVE-2023-2742
AI ChatBot < 4.5.5 - Admin+ Stored Cross-Site Scripting
Published 2023-06-19 · Modified
4.8EPSS 0.005
CVE-2023-2811
AI ChatBot < 4.5.6 - Admin+ Stored Cross-Site Scripting
Published 2023-06-19 · Modified
4.8EPSS 0.004
CVE-2023-1649
ChatBot < 4.5.1 - Admin+ Stored XSS
Published 2023-05-08 · Modified
4.8EPSS 0.004
CVE-2023-5606
The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions 4.8.6 through 4.9.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. NOTE: This vulnerability is a re-introduction of CVE-2023-4253.
Published 2023-11-02 · Modified
4.8EPSS 0.003
CVE-2025-0329
AI ChatBot for WordPress – WPBot < 6.2.4 - Admin+ Stored XSS
Published 2025-05-15 · Analyzed
4.8EPSS 0.003
CVE-2025-9111
WPBOT < 7.1.0 - Admin+ Stored XSS
Published 2025-09-09 · Modified
3.5EPSS 0.003