CVE-2026-16773
- EPSS 0.27%
- Veröffentlicht 28.07.2026 11:32:48
- Zuletzt bearbeitet 28.07.2026 20:17:24
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible fo...
CVE-2026-16774
- EPSS 0.24%
- Veröffentlicht 28.07.2026 11:32:47
- Zuletzt bearbeitet 28.07.2026 16:17:34
The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handler. This is due to the wpcs_send_email() function being registered on both wp_ajax_wpcs_send_email and...
CVE-2026-15610
- EPSS 0.23%
- Veröffentlicht 16.07.2026 07:51:05
- Zuletzt bearbeitet 16.07.2026 13:38:53
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.5.6. This is due to the plugin not properly verifying that a user is authorized t...
CVE-2026-15106
- EPSS 0.27%
- Veröffentlicht 16.07.2026 07:51:05
- Zuletzt bearbeitet 16.07.2026 13:38:53
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.5.6. This is due to the plugin not properly verifying that a user is authorized t...
CVE-2026-13731
- EPSS 0.66%
- Veröffentlicht 01.07.2026 03:43:34
- Zuletzt bearbeitet 01.07.2026 13:56:17
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conversation' parameter in all versions up to, and including, 8.4.9 due to insufficient input sanitizatio...
CVE-2025-9111
- EPSS 0.26%
- Veröffentlicht 09.09.2025 06:00:09
- Zuletzt bearbeitet 13.11.2025 21:15:55
The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capabilit...
CVE-2025-0329
- EPSS 0.26%
- Veröffentlicht 15.05.2025 20:16:01
- Zuletzt bearbeitet 12.06.2025 16:35:31
The AI ChatBot for WordPress WordPress plugin before 6.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capabilit...
CVE-2024-6669
- EPSS 0.33%
- Veröffentlicht 17.07.2024 07:15:03
- Zuletzt bearbeitet 08.04.2026 19:22:13
The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.5.7 due to insufficient input sanitization and output escaping. This makes it possible f...
CVE-2024-0453
- EPSS 0.36%
- Veröffentlicht 22.05.2024 04:15:09
- Zuletzt bearbeitet 08.04.2026 18:18:51
The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated...
CVE-2024-0452
- EPSS 0.36%
- Veröffentlicht 22.05.2024 04:15:09
- Zuletzt bearbeitet 08.04.2026 18:18:51
The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_upload_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated...