Critical vulnerability

CVE-2023-5241: The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up

Tracked since May 6, 2026

CVSS Breakdown

CVSS Base Score
Attack Vector
N/A
Requires physical access to exploit.
CIA Impact
Confidentiality N/A
Integrity N/A
Availability N/A

Exploit Probability (EPSS)

NaN%
NaN% probability of exploitation in 30 days
This vulnerability has a relatively low exploitation probability, but should still be patched according to your standard timelines.
Low

Insurance Impact Assessment

🛡️
Critical Impact

Critical vulnerabilities require urgent remediation. Insurers may impose coverage conditions, increased retentions, or exclusion endorsements until patches are applied.

CVE CVE-2023-5241 with CVSS 9.6. The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to append "<?php" to any existing file on the server resulting in potential DoS whe

Assess your exposure

Is your organization vulnerable? Run a free domain exposure scan to check.

← Back to Threat Feed