Wpbot
Vendor:
First CVE: Mar 29, 2023 · Active for 3 years
27
Total CVEs
More Total CVEs than 96% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wpbot over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 29, 2023
3 years ago
Most Recent CVE
Sep 9, 2025
318 days ago
CVE Severity & Scoring
Wpbot27 CVEs
59%
26%
11%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (40.7%)
Unknown0 (0.0%)
Required16 (59.3%)
Privileges Required
Low6 (22.2%)
High12 (44.4%)
None9 (33.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1650CRITICAL The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Objec | May 8, 2023 | 9.8 | 41 | NO | NO |
CVE-2023-5204HIGH The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied p | Oct 19, 2023 | 7.5 | 32 | NO | YES |
CVE-2023-5533CRITICAL The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks on the corresponding functions in versions up to, and includi | Oct 20, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-5212HIGH The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as well as version 4.9.2. This makes it possible for authentica | Oct 19, 2023 | 8.1 | 27 | NO | NO |
CVE-2024-22309CRITICAL Deserialization of Untrusted Data vulnerability in QuantumCloud ChatBot with AI.This issue affects ChatBot with AI: from n/a through 5.1.0. | Jan 24, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-5241HIGH The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. Th | Oct 19, 2023 | 8.1 | 26 | NO | NO |
CVE-2023-44993HIGH Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.7.8 versions. | Oct 9, 2023 | 8.8 | 24 | NO | NO |
CVE-2024-0453HIGH The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_callback function in all versions | May 22, 2024 | 7.7 | 22 | NO | NO |
CVE-2024-0452HIGH The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_upload_callback function in all versions | May 22, 2024 | 7.7 | 21 | NO | NO |
CVE-2023-48741HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud AI ChatBot.This issue affects AI ChatBot: from n/a through 4.7.8. | Dec 19, 2023 | 7.2 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (27 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.7% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (27 CVEs).
Media Mentions
Signals from CVEs in this product scope (27 CVEs).
Top CNAs Publishing CVEs For Wpbot
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.9.2 | 4 | 7.8 | 1.1% | 0 | 0 |