CVE-2024-6845

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Sep 25, 2024
Updated: Oct 7, 2024
CWE ID 862

Summary

CVE-2024-6845 is a vulnerability affecting the Chatbot with ChatGPT WordPress plugin before version 2.4.6. This issue allows unauthenticated users to access a REST endpoint without proper authorization. Successful exploitation grants attackers the ability to retrieve an encoded OpenAI API key. Subsequently, they can decode the key, resulting in unauthorized access to the plugin's OpenAI API. This vulnerability poses a significant risk for sensitive data exposure. It is recommended that users update their plugins to the latest version to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share