VYPR
Critical severity9.6NVD Advisory· Published Oct 19, 2023· Updated Apr 8, 2026

CVE-2023-5241

CVE-2023-5241

Description

The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to append "<?php" to any existing file on the server resulting in potential DoS when appended to critical files such as wp-config.php.

Affected products

2
  • cpe:2.3:a:quantumcloud:wpbot:*:*:*:*:*:wordpress:*:*+ 1 more
    • cpe:2.3:a:quantumcloud:wpbot:*:*:*:*:*:wordpress:*:*range: <4.9.1
    • cpe:2.3:a:quantumcloud:wpbot:4.9.2:*:*:*:*:wordpress:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.