VYPR
Unrated severityNVD Advisory· Published Sep 25, 2024· Updated Sep 25, 2024

SmartSearchWP < 2.4.6 - Unauthenticated OpenAI Key Disclosure

CVE-2024-6845

Description

The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.