Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-10705 2 Mxchat, Wordpress 2 Ai Chatbot For Wordpress, Wordpress 2025-10-24 5.3 Medium
The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.4.6. This is due to insufficient validation of user-supplied URLs in the PDF processing functionality. This makes it possible for unauthenticated attackers to make the WordPress server perform HTTP requests to arbitrary destinations via the mxchat_handle_chat_request AJAX action.