ChatBot plugin for WordPress up to 4.8.9 contains a sql_injection caused by insufficient escaping and lack of preparation on the $strid parameter, letting unauthenticated attackers extract sensitive data, exploit requires no authentication.
id: CVE-2023-5204
info:
name: WordPress AI ChatBot (WPBot) <= 4.8.9 - SQL Injection
author: Shi
...