Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesWPBot

WPBot vulnerabilities

WPBot has 20 known vulnerabilities in this database. The most recent published record is dated 16 Sep 2026.

Known vulnerabilities
20
Active installs
5,000+
Latest version
8.8.2
Last updated
30 Sep 2026
Most recent
16 Sep 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Broken access control
CVE-2026-87959
Medium 5.4Before 8.7.6Fixed in 8.7.616 Sep 2026
Sensitive data exposure
CVE-2026-87916
Medium 5.3Before 8.6.0Fixed in 8.6.012 Sep 2026
Broken access control
CVE-2026-87918
Medium 5.3Before 8.5.7Fixed in 8.5.712 Sep 2026
Cross-site scripting (XSS)
CVE-2026-83593
High 7.2Up to 8.7.3Fixed in a later version (latest 8.8.2)9 Sep 2026
Broken access control
CVE-2026-16774
Medium 5.3Up to 8.5.9Fixed in a later version (latest 8.8.2)28 Jul 2026
Sensitive data exposure
CVE-2026-16773
Medium 5.3Up to 8.5.9Fixed in a later version (latest 8.8.2)28 Jul 2026
SQL injection
CVE-2026-14189
Low 3.8Before 8.5.2Fixed in 8.5.227 Jul 2026
Broken access control
CVE-2026-14185
Medium 4.3Before 8.2.0Fixed in 8.2.021 Jul 2026
Broken access control
CVE-2026-15610
Medium 4.3Up to 8.5.6Fixed in a later version (latest 8.8.2)16 Jul 2026
Broken access control
CVE-2026-15106
Medium 5.3Up to 8.5.6Fixed in a later version (latest 8.8.2)16 Jul 2026
Cross-site scripting (XSS)
CVE-2026-13731
High 7.2Up to 8.4.9Fixed in a later version (latest 8.8.2)1 Jul 2026
Cross-site scripting (XSS)
CVE-2024-6669
Medium 5.5Before 5.5.8Fixed in 5.5.817 Jul 2024
Broken access control
CVE-2024-0451
Medium 5.0Before 5.3.6Fixed in 5.3.622 May 2024
Broken access control
CVE-2024-0452
Medium 5.0Before 5.3.6Fixed in 5.3.622 May 2024
Broken access control
CVE-2024-0453
Medium 5.0Before 5.3.6Fixed in 5.3.622 May 2024
Cross-site scripting (XSS)
CVE-2023-5691
Medium 4.4Up to 2.3.9Fixed in a later version (latest 8.8.2)11 Jan 2024
Sensitive data exposure
CVE-2023-5254
Medium 5.3Before 4.9.1Fixed in 4.9.119 Oct 2023
Arbitrary file deletion
CVE-2023-5212
Critical 9.6Before 4.9.1Fixed in 4.9.119 Oct 2023
Path traversal
CVE-2023-5241
Critical 9.6Before 4.9.1Fixed in 4.9.119 Oct 2023
SQL injection
CVE-2023-5204
Critical 9.8Before 4.9.1Fixed in 4.9.119 Oct 2023
Read the published descriptions
CVE-2026-87959, 16 Sep 2026
The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI provider settings, allowing users with subscriber-level access to overwrite those settings, including the API key used for the WPBot WordPress plugin before 8.7.6's outgoing AI requests. CVE record
CVE-2026-87916, 12 Sep 2026
The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every chat visitor by requesting a wide date range. CVE record
CVE-2026-87918, 12 Sep 2026
The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attackers to make those third-party API calls, and consume the associated cost, using the site's own configured API keys. CVE record
CVE-2026-83593, 9 Sep 2026
The WPBot - AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conversation' parameter in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The action is gated only by a nonce that is localized into every public-facing page via wp_localize_script, rendering the nonce check ineffective as an access control barrier for unauthenticated users. CVE record
CVE-2026-16774, 28 Jul 2026
The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handler. This is due to the wpcs_send_email() function being registered on both wp_ajax_wpcs_send_email and wp_ajax_nopriv_wpcs_send_email with no nonce verification, capability check, or rate limiting, while forwarding attacker-controlled recipient, subject, and body directly to wp_mail(). This makes it possible for unauthenticated attackers to send arbitrary emails to any recipient from the site's domain, enabling spam, phishing, and abuse that can lead to the site's IP/domain being blacklisted. CVE record
CVE-2026-16773, 28 Jul 2026
The WPBot - AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and associated user PII - including names, email addresses, and phone numbers - stored in the wpbot_user and wpbot_conversation tables to an attacker-controlled email address. CVE record
CVE-2026-14189, 27 Jul 2026
The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search. CVE record
CVE-2026-14185, 21 Jul 2026
The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-generation settings handlers, allowing authenticated users with subscriber-level access to modify the WPBot WordPress plugin before 8.2.0's configuration. CVE record
CVE-2026-15610, 16 Jul 2026
The WPBot - AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to trigger arbitrary re-embedding of stored RAG documents, modifying the rag_documents table and consuming the site owner's paid third-party AI API credits (OpenAI, Gemini, OpenRouter, or xAI). CVE record
CVE-2026-15106, 16 Jul 2026
The WPBot - AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to delete arbitrary chat session records from the wpbot_user and wpbot_conversation tables, including chat history and conversation logs, by supplying a crafted userid value. CVE record
CVE-2026-13731, 1 Jul 2026
The WPBot - AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conversation' parameter in all versions up to, and including, 8.4.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The AJAX nonce required to authenticate the save request is publicly emitted on every frontend page via wp_localize_script, making it freely obtainable by any anonymous visitor and removing any practical barrier to exploitation. CVE record
CVE-2024-6669, 17 Jul 2024
The AI ChatBot for WordPress - WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. CVE record
CVE-2024-0451, 22 May 2024
The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the openai_file_list_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to list files existing in a linked OpenAI account. CVE record
CVE-2024-0452, 22 May 2024
The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_upload_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files to a linked OpenAI account. CVE record
CVE-2024-0453, 22 May 2024
The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete files from a linked OpenAI account. CVE record
CVE-2023-5691, 11 Jan 2024
The Chatbot for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version 2.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. CVE record
CVE-2023-5254, 19 Oct 2023
The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9 via the qcld_wb_chatbot_check_user function. This can allow unauthenticated attackers to extract sensitive data including confirmation as to whether a user name exists on the site as well as order information for existing users. CVE record
CVE-2023-5212, 19 Oct 2023
The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as well as version 4.9.2. This makes it possible for authenticated attackers with subscriber privileges to delete arbitrary files on the server, which makes it possible to take over affected sites as well as others sharing the same hosting account. Version 4.9.1 originally addressed the issue, but it was reintroduced in 4.9.2 and fixed again in 4.9.3. CVE record
CVE-2023-5241, 19 Oct 2023
The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to append "<?php" to any existing file on the server resulting in potential DoS when appended to critical files such as wp-config.php. CVE record
CVE-2023-5204, 19 Oct 2023
The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record

What to do if you run WPBot

If you run WPBot, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new WPBot vulnerabilities

Free. We email you when a new vulnerability is published for WPBot, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support