CVE-2024-6843: The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not sanitise and escape user inputs, which could allow unaut
Summary
The Chatbot with ChatGPT WordPress plugin before version 2.4.5 has a vulnerability where it does not properly clean and escape user inputs, allowing attackers to perform Stored Cross-Site Scripting attacks (XSS, a type of attack where malicious code gets saved and runs when admins view it) without needing to be logged in.
Solution / Mitigation
Update the Chatbot with ChatGPT WordPress plugin to version 2.4.5 or later.
Vulnerability Details
6.1(medium)
EPSS: 1.8%
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-6843
First tracked: February 15, 2026 at 08:50 PM
Classified by LLM (prompt v3) · confidence: 72%