Chatbot with ChatGPT WordPress Plugin API Key Leak Vulnerability (CVE-2024-6845) — Medium Severity

A notable security flaw, identified as CVE-2024-6845, has been discovered in the popular Chatbot with ChatGPT WordPress plugin. This vulnerability could allow unauthorized individuals to access your OpenAI API key, posing a risk to the security of your WordPress site and your associated OpenAI services.

In simple terms, this plugin had a security loophole in one of its behind-the-scenes communication channels (a REST endpoint). This flaw meant that even visitors who weren’t logged into your website could find a hidden, encoded key. Once retrieved, this key could be easily decoded to reveal your sensitive OpenAI API key, potentially leading to its misuse.

CVE Details

  • Product Name: Chatbot with ChatGPT WordPress plugin
  • Published: September 25, 2024
  • Severity: Medium
  • Status: Analyzed

Affected Products

The vulnerability impacts the Chatbot with ChatGPT WordPress plugin. Specifically, any versions of this plugin prior to 2.4.6 are affected.

Current Status

The vulnerability has been officially analyzed and assigned a CVE ID. Details regarding the nature of the flaw are publicly available, along with information on how to address it.

Severity Level

This vulnerability is rated as Medium severity, with a CVSS score of 5.3. A medium severity rating indicates that while the vulnerability is not the most critical, it still presents a significant risk. An attacker could exploit this flaw without needing any special access or authentication, potentially leading to unauthorized use of your OpenAI API key, which could incur unexpected costs or expose data depending on the API key’s permissions.

Possible Solutions

The good news is that a fix is available. To protect your WordPress site and your OpenAI API key from this vulnerability, you should update the Chatbot with ChatGPT plugin to version 2.4.6 or higher immediately. Always back up your website before performing any plugin updates.

References

https://wpscan.com/vulnerability/cfaaa843-d89e-42d4-90d9-988293499d26/

https://nvd.nist.gov/vuln/detail/CVE-2024-6845

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.