KalravAI Agent
KalravAI Agent has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of September 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.
The most common weakness is Unrestricted Upload Of File With Dangerous Type, behind 1 of the records (100%).
The one issue recorded for KalravAI Agent has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.
All of these findings were reported by Ryan Kozak. The current release is tested up to WordPress 7.0.4.
CVE-2025-13374Kalrav AI Agent <= 2.3.3 - Unauthenticated Arbitrary File Upload via kalrav_upload_file AJAX Action
Read the full analysisVulnerability Records

KalravAI Agent
Author
irisideatechsolutions
Interactive Chat Interface – A modern, fully customizable chat window that integrates beautifully with your website’s layout and style. Quick & Easy Setup – Simply install, activate, and start chatting — your AI assistant is ready within minutes, no coding needed. Intelligent Conversations – Engage visitors with fast, natural, and context-aware responses powered by advanced AI technology. Flexible Customization – Personalize Common questions, icons, and greetings to perfectly reflect Kalrav AI identity. Smart Engagement Triggers – Automatically welcome visitors, collect leads, or reply to common questions with ease. Lightweight & Secure – Built for speed, stability, and privacy, ensuring smooth performance across all devices. External Services The external service used: Service Name: Kalrav.ai Purpose: To process and respond to user messages in the chat widget. Data Sent: User message, session ID (anonymous), and site identifier. Data Received: AI-generated response content. Please check our privacy policy and terms of services: Privacy policy : https://kalrav.ai/privacy-policy/ Terms Of service : https://kalrav.ai/terms-of-services/ No personal data is stored or shared with third parties. License GPLv2 or later. See license.txt.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C