Vulnerability Description
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Webdigit | Chatbot With Chatgpt | < 2.4.5 |
References
- https://wpscan.com/vulnerability/d48fdab3-669c-4870-a2f9-6c39a7c25fd8/ExploitThird Party Advisory
FAQ
What is CVE-2024-6846?
CVE-2024-6846 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs
How severe is CVE-2024-6846?
CVE-2024-6846 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-6846?
Check the references section above for vendor advisories and patch information. Affected products include: Webdigit Chatbot With Chatgpt.