Impact
The WPBot plugin fails to verify that a user is authorised to delete chat sessions, which allows unauthenticated attackers to remove arbitrary records from the wpbot_user and wpbot_conversation tables. This results in loss of chat information that was stored in those logs.
Affected Systems
WordPress sites that have installed the WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin, specifically all versions up to and including 8.5.6.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS of < 1 % suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by sending a crafted HTTP request to the chat-sessions deletion endpoint with a userid parameter, without needing any authentication. The exploit is straightforward and requires only knowledge of the endpoint URL and the ability to send a request.
OpenCVE Enrichment