CVE 4.3 MEDIUM

AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant <= 1.6.5 - Unauthenticated CSV Injection_CVE-2025-11576

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Description

The AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.6.5. This is due to insufficient sanitization in the 'newcodebyte_chatbot_export_messages' function. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

Basic Information

ID CVE-2025-11576
Source Wordfence
Published Oct 24, 2025 at 12:29
Modified Oct 24, 2025 at 12:48

Affected Product

Vendor newcodebyte
Product AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant
Version *
Affected Versions newcodebyte AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.