CyberRota Analysis
AI-GeneratedThe AI ChatBot for WooCommerce plugin for WordPress prior to version 4.8.4 is vulnerable due to a lack of authorization and nonce checks on specific AJAX actions. This flaw allows unauthenticated users to exploit the site owner's stored third-party API key, potentially incurring charges to the owner's account and accessing sensitive knowledge-base content. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to retrieve indexed knowledge-base content.