Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical1
High0
Medium3
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2026-01-20

CVE-2024-6845 - Chatbot With Chatgpt Plugin

The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key

PLUGIN Chatbot With Chatgpt

CVE-2024-6845

MEDIUM CVSS 5.3 2024-09-25
Threat Entry Updated 2025-05-27

CVE-2024-6847 - Chatbot With Chatgpt Plugin

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.

PLUGIN Chatbot With Chatgpt

CVE-2024-6847

CRITICAL CVSS 9.8 2024-08-20
Threat Entry Updated 2025-05-27

CVE-2024-6843 - Chatbot With Chatgpt Plugin

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not sanitise and escape user inputs, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins

PLUGIN Chatbot With Chatgpt

CVE-2024-6843

MEDIUM CVSS 6.1 2024-08-19
Scroll to top