Pricing
Case studies
Login
Start trial
ChatBot
QuantumCloud
Developer
7.9.5
Latest version
6,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
32 patched
11 Mitigation rules
SQL Injection vulnerability
<= 7.7.9
20/03/2026
Missing Authorization via openai_file_delete_callback vulnerability
<= 5.3.4
03/02/2026
Missing Authorization via openai_file_list_callback vulnerability
<= 5.3.4
03/02/2026
Broken Access Control vulnerability
<= 7.7.3
13/10/2025
Broken Access Control vulnerability
<= 7.3.9
12/10/2025
Admin+ Stored XSS vulnerability
< 7.1.0
09/09/2025
Broken Access Control Vulnerability
<= 6.7.3
27/06/2025
Admin+ Stored XSS vulnerability
< 6.2.4
19/05/2025
Local File Inclusion vulnerability
<= 6.3.5
23/02/2025
Authenticated (Administrator+) Stored Cross-Site Scripting vulnerability
<= 5.5.7
17/07/2024
Missing Authorization via multiple functions vulnerability
<= 5.3.4
22/05/2024
Unauthenticated PHP Object Injection vulnerability
<= 5.4.5
19/01/2024
SQL Injection vulnerability
<= 4.7.8
23/11/2023
Wordpress ChatBot plugin 4.8.6 - 4.9.6 - Authenticated (Administrator+) Stored Cross-Site Scripting in FAQ Builder vulnerability
4.8.6-4.9.6
02/11/2023
Unauthenticated SQL Injection via qc_wpbo_search_response vulnerability
<= 4.8.9
12/10/2023
Authenticated (Subscriber+) Arbitrary File Deletion via qcld_openai_delete_training_file vulnerability
<= 4.8.9
12/10/2023
Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_file vulnerability
<= 4.8.9
12/10/2023
Cross-Site Request Forgery on AJAX actions vulnerability
<= 4.8.9
12/10/2023
Missing Authorization on AJAX actions vulnerability
<= 4.8.9
12/10/2023
Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_user vulnerability
<= 4.8.9
12/10/2023
Cross Site Request Forgery (CSRF) vulnerability
<= 4.7.8
02/10/2023
Admin+ Stored XSS in Language Settings vulnerability
< 4.7.8
10/08/2023
Admin+ Stored XSS in FAQ Builder vulnerability
< 4.7.8
10/08/2023
Admin+ Stored Cross-Site Scripting vulnerability
< 4.5.5
19/06/2023
Admin+ Stored Cross-Site Scripting vulnerability
< 4.5.6
19/06/2023
Auth. OpenAI Settings Update to Stored XSS vulnerability
<= 4.4.8
20/04/2023
Unauthenticated Stored XSS vulnerability
<= 4.4.8
20/04/2023
Unauth. PHP Object Injection vulnerability
<= 4.4.6
20/04/2023
Stored XSS via CSRF vulnerability
<= 4.4.4
20/04/2023
Missing Authorization on openai_settings_option_callback vulnerability
<= 4.4.7
30/03/2023
Multiple Cross Site Scripting (XSS)
<= 4.3.0
27/01/2023
Cross Site Request Forgery (CSRF)
<= 4.2.8
27/01/2023