The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs.
id: CVE-2024-6846
info:
name: SmartSearchWP <= 2.4.4 - Unauthenticated Log Purge
author: s4e-io
...