The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Object Injection when a suitable gadget is present on the blog
| Software | From | Fixed in |
|---|---|---|
| quantumcloud / wpbot | - | 4.4.7 |