Description
The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9 via the qcld_wb_chatbot_check_user function. This can allow unauthenticated attackers to extract sensitive data including confirmation as to whether a user name exists on the site as well as order information for existing users.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57579 | The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9 via the qcld_wb_chatbot_check_user function. This can allow unauthenticated attackers to extract sensitive data including confirmation as to whether a user name exists on the site as well as order information for existing users. |
References
History
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | AI ChatBot <= 4.8.9 - Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_user | |
| Weaknesses | CWE-200 |
Mon, 12 May 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Quantumcloud wpbot
|
|
| CPEs | cpe:2.3:a:quantumcloud:wpbot:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Quantumcloud ai Chatbot
|
Quantumcloud wpbot
|
Wed, 05 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:26:54.231Z
Reserved: 2023-09-28T13:51:14.299Z
Link: CVE-2023-5254
Updated: 2024-08-02T07:52:08.517Z
Status : Modified
Published: 2023-10-19T06:15:12.103
Modified: 2026-04-08T19:18:45.207
Link: CVE-2023-5254
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD