S4E just found a critical-severity finding from cve-2022-27924 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2024-6845 Scanner

CVE-2024-6845 Scanner - Information Disclosure vulnerability in SmartSearchWP

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-6845
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Chatbot with ChatGPT WordPress
AFFECTED< 2.4.6SAFE ✓≥ 2.4.6
chatbot_with_chatgpt_wordpressby smartsearchwp
AFFECTED< 2.4.6SAFE ✓≥ 2.4.6
Updated Aug 22, 2026View on NVD →
Detail

SmartSearchWP is a plugin developed by WebDigit for enhancing search functionalities in WordPress websites. It is most commonly used by web administrators and developers looking to implement advanced search capabilities. The plugin integrates smoothly with WordPress, offering customizable search results and flexible API integrations. Administrators find it beneficial for tailoring search functionalities to specific site needs. It’s widely used for its efficient search management and seamless integration with other WordPress components. The primary goal of using SmartSearchWP is to provide users with an enhanced, accurate, and fast search experience on WordPress-based sites.

The detected vulnerability is an Information Disclosure issue. This specific flaw allows unauthenticated users to retrieve an encoded OpenAI API key via an unprotected REST endpoint. The lack of proper authorization mechanisms at a vulnerable endpoint is the source of this compromise. Attackers can exploit this flaw to decode and use the API key without permission. Such vulnerabilities can lead to unauthorized access to sensitive data or services through exposed API keys. This vulnerability highlights the importance of securing API endpoints to safeguard sensitive information.

The technical details of the vulnerability show that it resides in one of the plugin's REST API endpoints. Unauthenticated users can make a POST request to a specific endpoint and retrieve the encoded OpenAI API key. The endpoint lacks necessary authorization checks, enabling unauthorized access. By analyzing network traffic or guessing the endpoint, malicious users can decode the key easily. This flaw makes the OpenAI API vulnerable to abuse and misuse, as the key grants access to potentially sensitive services. The vulnerability is confirmed by checking the endpoint for expected responses and verifying the presence of the encoded key.

If exploited, this Information Disclosure vulnerability can have several consequences. Unauthorized parties may gain access to sensitive data or functionalities that the API key provides. It can lead to the abuse and overuse of the OpenAI API services, potentially incurring financial costs or operational disturbances. Furthermore, this exposure increases the risk of additional vulnerabilities being discovered, as an attacker with access might be able to gather more information about the system. Overall, it compromises the integrity, confidentiality, and possibly the availability of services depending on the OpenAI API integration.

REFERENCES

Solution Advice
  • Ensure all REST API endpoints have proper authorization checks in place.
  • Regularly update to the latest versions to benefit from patches and improvements.
  • Restrict access to sensitive data using robust access control mechanisms.
  • Employ encryption techniques to safeguard encoded keys and sensitive information.
  • Implement security monitoring to detect unusual access patterns or misuse.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.