Impact
An unauthenticated reflected cross‑site scripting flaw exists in the WordPress ChatBot plugin through version 8.3.2. The flaw permits an attacker to inject arbitrary JavaScript into user‑controlled input that is subsequently displayed by the plugin without proper sanitization, aligning with CWE‑79. Successful exploitation allows the execution of attacker‑supplied code in the context of a visitor’s browser, which can lead to session hijacking, data theft, or site defacement.
Affected Systems
QuantumCloud’s ChatBot plug‑in bundled with WordPress that has installed the ChatBot plugin version 8.3.2 or earlier is vulnerable and should determine the exact version installed to confirm exposure.
Risk and Exploitability
The CVSS score of 7.1 indicates medium‑to‑high risk, and the EPSS score of < 1% suggests a low but non‑zero probability of exploitation today. Based on the description, it is inferred that the attack vector is remote delivery of a crafted payload via a URL or form field any site visitor. The flaw is not listed in the CISA KEV catalog, yet its straightforward attack surface and potential for wide impact warrant prompt remediation.
OpenCVE Enrichment