Impact
The Kognetiks Chatbot WordPress plugin permits attackers without authentication to bypass authorization checks and upload a restricted set of files that the plugin deems safe. In addition, an unauthenticated attacker can invoke the delete function to erase all stored conversation data. This missing capability verification is a classic unauthorized access flaw, classified as CWE‑285, allowing data modification and loss of user interactions, which may compromise confidentiality or disrupt service continuity.
Affected Systems
WordPress installations that use the Kognetiks Chatbot plugin, versions 2.3.5 and earlier, are impacted by this vulnerability.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while an EPSS score of less than 1% suggests a very low likelihood of exploitation. The flaw is not currently listed in the CISA KEV catalog, meaning it has not been widely observed in the wild. Attackers can exploit the issue unauthenticated through web requests to the plugin’s upload or conversation‑erase endpoints, and doing so requires only internet access to the affected WordPress site.
OpenCVE Enrichment