CVE-2023-1651
Quantumcloud Wpbot ≤ 4.4.9
Raw vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NSummary
CVE-2023-1651 is a medium-severity an unspecified weakness vulnerability in Quantumcloud Wpbot. Its CVSS base score is 5.4 (Medium).
Operationally, ranked at the 16th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
This vulnerability is AI-related — categorised as LLM Application Platforms.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-23880
Vulnerability Data
The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in the AJAX action responsible to update the OpenAI settings, allowing any authenticated users, such as subscriber to update them. Furthermore, due to the lack of escaping…
more
of the settings, this could also lead to Stored XSS
- CWE(s)
AI Security AnalysisAI
- AI Category
- LLM Application Platforms
- Risk Domain
- N/A
- OWASP Top 10 for LLMs 2025
- None mapped
- Classification Reason
- Matched keywords: ai, openai
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.