4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Description
The AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.6.5. This is due to insufficient sanitization in the 'newcodebyte_chatbot_export_messages' function. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Basic Information
ID
CVE-2025-11576
Source
Wordfence
Published
Oct 24, 2025 at 12:29
Modified
Oct 24, 2025 at 12:48
Affected Product
Vendor
newcodebyte
Product
AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant
Version
*
Affected Versions
newcodebyte AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant *