CVE Database
/

CVE-2024-6845

Back to search

CVE-2024-6845

Published: Sep 25, 2024

Modified: Sep 25, 2024

PUBLISHED

Description

The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key

VendorProductVersions

Unknown

Chatbot with ChatGPT WordPress

affected
0 - < 2.4.6

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now