WordPress 的 Chatbot 插件在 8.5.9 及以下版本中存在缺乏身份验证的漏洞。该漏洞通过 wpcs_send_email() AJAX 处理器利用。由于 wpcs_send_email() 函数在 wp_ajax_wpcs_send_email 和 wp_ajax_nopriv_wpcs_send_email 中注册,但既没有验证 nonce,也没有进行权限检查或速率限制,同时直接将攻击者控制的收件人、主题和内容转发到 wp_mail(),因此未认证的攻击者可以随意发送来自该网站域名的任意邮件给任
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| quantumcloud | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | ≤ 8.5.9 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| quantumcloud | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | 0 ~ 8.5.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet