Impact
The WPBot plugin before version 8.2.0 lacks a capability check in one of its retrieval‑augmented‑generation settings handlers, allowing authenticated users who hold the subscriber role to alter the plugin’s configuration. This can lead to unauthorized changes in the chatbot’s behavior and potentially disrupt site management. The weakness is a classic missing authorization flaw (CWE‑862).
Affected Systems
All WordPress sites running the WPBot plugin with a version earlier than 8.2.0 are vulnerable, regardless of the specific minor or patch revision. The issue applies to all sites that grant subscriber access, as the subscriber role is the minimum capability required to exploit the flaw.
Risk and Exploitability
The CVSS score of 4.3 and a very low EPSS score of less than 1% indicate a moderate risk and an unlikely immediate exploitation window. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation. Because the flaw requires an authenticated subscriber credential, the most probable attack vector is via legitimate user interaction with the plugin settings interface or by sending a crafted request directly to the RAG settings handler.
OpenCVE Enrichment