Junglewise Threat Intelligence

CVE-2024-32729: QuantumCloud Conversational Forms for ChatBot path traversal

CVE-2024-32729 · Severity: high · CVSS 7.5 · Published 2026-06-17

Vendors: QuantumCloud.

Executive brief

QuantumCloud Conversational Forms for ChatBot is a WordPress plugin used to create interactive forms for website chatbots. A security flaw in this plugin allows an attacker to download sensitive files from the web server without needing to log in. This could lead to the exposure of configuration files, database credentials, or other private site data, potentially compromising the entire website.

Technical details

A path traversal vulnerability (CWE-22) exists in the QuantumCloud Conversational Forms for ChatBot plugin for WordPress in versions up to and including 1.1.8. The flaw stems from improper limitation of pathnames, allowing an unauthenticated remote attacker to perform arbitrary file downloads. By sending a specially crafted request, an attacker can traverse the directory structure and access files outside of the intended directory, such as wp-config.php. This vulnerability is exploitable over the network without user interaction. The issue has been addressed in version 1.2.0.

Affected products

  • QuantumCloud Conversational Forms for ChatBot up to 1.1.8

Timeline

  • 2024-01-29: other: Reported by Yudistira Arya
  • 2024-04-22: advisory: Initial disclosure by Patchstack
  • 2026-06-17: disclosed: NVD publication date

References