Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57568 | The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to append "<?php" to any existing file on the server resulting in potential DoS when appended to critical files such as wp-config.php. |
Wed, 08 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | AI ChatBot <= 4.8.9 and 4.9.2 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_file |
Thu, 12 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 12 May 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Quantumcloud wpbot
|
|
| CPEs | cpe:2.3:a:quantumcloud:ai_chatbot:4.9.2:*:*:*:*:wordpress:*:* |
cpe:2.3:a:quantumcloud:wpbot:*:*:*:*:*:wordpress:*:* cpe:2.3:a:quantumcloud:wpbot:4.9.2:*:*:*:*:wordpress:*:* |
| Vendors & Products |
Quantumcloud ai Chatbot
|
Quantumcloud wpbot
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:42:20.846Z
Reserved: 2023-09-27T18:46:43.130Z
Link: CVE-2023-5241
Updated: 2024-08-02T07:52:08.533Z
Status : Modified
Published: 2023-10-19T06:15:11.690
Modified: 2026-04-08T17:17:06.743
Link: CVE-2023-5241
No data.
OpenCVE Enrichment
No data.
EUVD