CVE-2023-2399: qubotchat < 1.1.6 - Unauthenticated Stored XSS

0.0 CVSS

Description

The QuBot WordPress plugin before 1.1.6 doesn't filter user input on chat, leading to bad code inserted on it be reflected on the user dashboard.

Classification

CVE ID: CVE-2023-2399

CVSS Base Severity: LOW

CVSS Base Score: 0.0

Affected Products

Vendor: Unknown

Product: QuBot

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.07% (probability of being exploited)

EPSS Percentile: 34.0% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://wpscan.com/vulnerability/deca3cd3-f7cf-469f-9f7e-3612f7ae514d

Timeline