Description
Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 7.3.9.
Published: 2025-11-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw that permits attackers to exploit incorrectly configured access control security levels within the QuantumCloud ChatBot plugin. This flaw can allow an attacker to access or perform actions that they should not be permitted to, potentially leading to unauthorized data exposure or manipulation of chatbot behavior. The weakness is classified under CWE-862, indicating that the application does not enforce proper authorization checks for users with insufficient privileges.

Affected Systems

The affected component is the QuantumCloud ChatBot plugin used within WordPress installations. All versions from the earliest available release through version 7.3.9 are vulnerable. The plugin is distributed for WordPress sites and may be present on any site that has installed the ChatBot addon up to and including the listed maximum version.

Risk and Exploitability

The CVSS score of 5.3 reflects a moderate severity rating, while an EPSS score of <1% and the fact that it is not listed in the CISA KEV catalog suggest that the likelihood of exploitation is currently low. The vulnerability’s impact is tied to broken access controls, meaning penalties primarily involve unauthorized access to protected resources or operations rather than remote code execution. The likely attack vector is through the web-based plugin interface and is inferred to require authentication of a user with a role that does not have sufficient permissions; however, the exact exploitation path is not explicitly described in the advisory.

Generated by OpenCVE AI on April 29, 2026 at 20:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the QuantumCloud ChatBot plugin to any version newer than 7.3.9 where the access control fix is applied.
  • If an upgrade is not possible, disable or remove the ChatBot plugin from the WordPress installation to eliminate the vulnerable code path.
  • Review and reconfigure the plugin’s access control settings to ensure that only authorized users can execute privileged actions, and verify that role permissions are correctly applied throughout the WordPress site.

Generated by OpenCVE AI on April 29, 2026 at 20:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Quantumcloud
Quantumcloud chatbot
Wordpress
Wordpress wordpress
Vendors & Products Quantumcloud
Quantumcloud chatbot
Wordpress
Wordpress wordpress

Thu, 13 Nov 2025 09:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 7.3.9.
Title WordPress ChatBot plugin <= 7.3.9 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Quantumcloud Chatbot
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:13.339Z

Reserved: 2025-10-29T03:08:27.752Z

Link: CVE-2025-64277

cve-icon Vulnrichment

Updated: 2025-11-13T16:03:53.521Z

cve-icon NVD

Status : Deferred

Published: 2025-11-13T10:15:53.113

Modified: 2026-04-27T16:16:39.663

Link: CVE-2025-64277

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T20:15:19Z

Weaknesses