Description
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to delete arbitrary chat session records from the wpbot_user and wpbot_conversation tables, including chat history and conversation logs, by supplying a crafted userid value.
Published: 2026-07-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WPBot plugin fails to verify that a user is authorised to delete chat sessions, which allows unauthenticated attackers to remove arbitrary records from the wpbot_user and wpbot_conversation tables. This results in loss of chat information that was stored in those logs.

Affected Systems

WordPress sites that have installed the WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin, specifically all versions up to and including 8.5.6.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS of < 1 % suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by sending a crafted HTTP request to the chat-sessions deletion endpoint with a userid parameter, without needing any authentication. The exploit is straightforward and requires only knowledge of the endpoint URL and the ability to send a request.

Generated by OpenCVE AI on July 31, 2026 at 02:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update WPBot to the latest version that includes the fix, ensuring it is newer than 8.5.6.
  • Restrict the chat‑session deletion functionality to authenticated administrators only, either by configuring the plugin or adding a custom stop‑gap script that checks user capabilities before processing the request.
  • Enable logging and monitoring for attempts to access the chat‑session deletion endpoint and alert administrators to suspicious activity.

Generated by OpenCVE AI on July 31, 2026 at 02:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Quantumcloud
Quantumcloud wpbot – Ai Chatbot For Live Support, Lead Generation, Ai Services
Wordpress
Wordpress wordpress
Vendors & Products Quantumcloud
Quantumcloud wpbot – Ai Chatbot For Live Support, Lead Generation, Ai Services
Wordpress
Wordpress wordpress

Thu, 16 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Description The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to delete arbitrary chat session records from the wpbot_user and wpbot_conversation tables, including chat history and conversation logs, by supplying a crafted userid value.
Title WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameter
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Quantumcloud Wpbot – Ai Chatbot For Live Support, Lead Generation, Ai Services
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-16T12:38:20.321Z

Reserved: 2026-07-08T17:07:24.977Z

Link: CVE-2026-15106

cve-icon Vulnrichment

Updated: 2026-07-16T12:38:14.455Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T02:15:06Z

Weaknesses