CVE-2024-6846

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:webdigit:chatbot_with_chatgpt:*:*:*:*:*:wordpress:*:*

History

16 May 2025, 20:21

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Webdigit
Webdigit chatbot With Chatgpt
References () https://wpscan.com/vulnerability/d48fdab3-669c-4870-a2f9-6c39a7c25fd8/ - () https://wpscan.com/vulnerability/d48fdab3-669c-4870-a2f9-6c39a7c25fd8/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:webdigit:chatbot_with_chatgpt:*:*:*:*:*:wordpress:*:*

05 Sep 2024, 14:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

05 Sep 2024, 12:53

Type Values Removed Values Added
Summary
  • (es) El Chatbot con el complemento ChatGPT de WordPress anterior a la versión 2.4.5 no valida el acceso en algunas rutas REST, lo que permite que un usuario no autenticado elimine los registros de errores y chats.

05 Sep 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-05 06:15

Updated : 2025-05-16 20:21


NVD link : CVE-2024-6846

Mitre link : CVE-2024-6846

CVE.ORG link : CVE-2024-6846


JSON object : View

Products Affected

webdigit

  • chatbot_with_chatgpt