CVE-2024-13091 is a critical arbitrary file upload vulnerability affecting the WPBot Pro Wordpress Chatbot plugin, specifically within the 'qcld_wpcfb_file_upload' function, in all versions up to and including 13.5.4. This flaw allows unauthenticated attackers to upload arbitrary files to the server, potentially leading to remote code execution. The exploit requires the ChatBot Conversational Forms plugin and the Conversational Form Builder Pro addon. With a CVSS score of 9.8 (Critical), this vulnerability has a network attack vector and low attack complexity, requiring no user interaction or privileges. Its impact is high across confidentiality, integrity, and availability. The FAUCET Risk Score is 87/100, and its EPSS score indicates a higher exploitability probability than 94% of all CVEs. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for the vast majority of vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.5.6CPE matchmatch criteria | cpe:2.3:a:wpbot:wpot:*:*:*:*:pro:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.