The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key
History

Mon, 07 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Smartsearchwp smartsearchwp
Weaknesses CWE-862
CPEs cpe:2.3:a:smartsearchwp:smartsearchwp:*:*:*:*:*:wordpress:*:*
Vendors & Products Smartsearchwp smartsearchwp

Wed, 25 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Smartsearchwp
Smartsearchwp chatbot With Chatgpt Wordpress
CPEs cpe:2.3:a:smartsearchwp:chatbot_with_chatgpt_wordpress:*:*:*:*:*:*:*:*
Vendors & Products Smartsearchwp
Smartsearchwp chatbot With Chatgpt Wordpress
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Sep 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key
Title SmartSearchWP < 2.4.6 - Unauthenticated OpenAI Key Disclosure
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-09-25T06:00:04.626Z

Updated: 2024-09-25T13:43:40.694Z

Reserved: 2024-07-17T18:32:57.554Z

Link: CVE-2024-6845

cve-icon Vulnrichment

Updated: 2024-09-25T13:43:34.730Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-25T06:15:05.557

Modified: 2024-10-07T16:58:39.060

Link: CVE-2024-6845

cve-icon Redhat

No data.