The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 27 May 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Webdigit
Webdigit chatbot With Chatgpt
Weaknesses CWE-89
CPEs cpe:2.3:a:webdigit:chatbot_with_chatgpt:*:*:*:*:*:wordpress:*:*
Vendors & Products Webdigit
Webdigit chatbot With Chatgpt

Tue, 20 Aug 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Smartsearchwp
Smartsearchwp chatbot With Chatgpt Wordpress
CPEs cpe:2.3:a:smartsearchwp:chatbot_with_chatgpt_wordpress:*:*:*:*:*:*:*:*
Vendors & Products Smartsearchwp
Smartsearchwp chatbot With Chatgpt Wordpress
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 20 Aug 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.
Title SmartSearch WP <= 2.4.4 - Unauthenticated SQLi
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-20T18:50:30.236Z

Reserved: 2024-07-17T18:48:10.771Z

Link: CVE-2024-6847

cve-icon Vulnrichment

Updated: 2024-08-20T18:50:25.304Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-20T06:15:05.470

Modified: 2025-05-27T20:49:37.690

Link: CVE-2024-6847

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.