Critical severity9.8NVD Advisory· Published Jan 22, 2025· Updated Jun 17, 2026
CVE-2024-13091
CVE-2024-13091
Description
The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'qcld_wpcfb_file_upload' function in all versions up to, and including, 13.5.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The exploit requires thee ChatBot Conversational Forms plugin and the Conversational Form Builder Pro addon plugin.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- QuantumCloud/WPBot Pro Wordpress Chatbotv5Range: 0
Patches
Vulnerability mechanics
References
2- www.wordfence.com/threat-intel/vulnerabilities/id/0f9b6979-2662-4d2f-9656-b880dd80832cnvdThird Party Advisory
- www.wpbot.pronvdProduct
News mentions
0No linked articles in our index yet.