Input validation vulnerability in AI ChatBot 4.7.7

The ChatBot for WordPress is vulnerable to a type of security issue called Stored Cross-Site Scripting (also known as XSS). This means that in versions up to, and including, 4.7.7, an attacker with administrator-level permissions or higher could inject malicious code into pages on the website. This malicious code could then execute when any user visits the page, potentially allowing the attacker to gain access to sensitive information. This issue only affects WordPress installations that have the multi-site feature enabled and also have the “unfiltered_html” feature disabled.

Detected in:

AI ChatBot fixed vulnerable versions: >= * <= 4.7.7
AI ChatBot – WPBot fixed vulnerable versions:
AI ChatBot for WordPress – WPBot fixed vulnerable versions:
ChatBot with AI fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.