Impact
The vulnerability is a stored cross‑site scripting flaw where input provided to the QuantumCloud ChatBot plugin is saved in the database without proper neutralization and then rendered in web pages viewed by other users. Attackers can embed malicious scripts that execute in the browsers of anyone who accesses the affected page, potentially hijacking user sessions, defacing content, or exfiltrating data presented on the site. This weakness is identified as CWE‑79, Improper Neutralization of Input During Web Page Generation.
Affected Systems
QuantumCloud’s ChatBot WordPress plugin is affected in all releases up through version 8.3.7. No earlier version boundary is specified, so any installation of the plugin that is equal to or older than 8.3.7 is vulnerable. The plugin operates within standard WordPress installations and stores user‑supplied content in the database.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score is below 1%, suggesting a low probability of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is through the plugin’s web interface; an attacker only needs the ability to submit data that will be stored and later rendered, without requiring administrative privileges.
OpenCVE Enrichment