Description
The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to retrieve indexed knowledge-base content.
Published: 2026-08-02
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The exploited vulnerability resides in the AI ChatBot for WooCommerce plugin, where one AJAX action lacks both authorization and nonce verification. As a result, anyone on the internet can trigger this action and make the plugin send requests through the site owner's third‑party Gemini API key, incurring costs on the owner’s account. If an optional feature is enabled, the attacker can also pull content from the plugin’s indexed knowledge‑base, giving them access to proprietary information. This combination creates clear risks of financial abuse and data exposure for the website owner.

Affected Systems

Any WordPress site running the AI ChatBot for WooCommerce plugin version earlier than 4.8.4 is affected. The vulnerability is specifically tied to the "qcld_gemini_response" AJAX action within this plugin. No other vendors or products are listed in the CNA data, so the impact is confined to this single WordPress plugin implementation.

Risk and Exploitability

The CVSS score is 7.5, indicating high severity, but the EPSS score of less than 1% indicates a low current exploitation probability. The vulnerability is not present in the CISA KEV catalog. Attackers can freely invoke the vulnerable AJAX endpoint because no authentication or nonce is required, meaning the attack can originate from any web source and does not need privileged access to the site. Once executed, the plugin will forward the request to the Gemini service under the site owner's billing, and when the optional feature is active, the attacker can read sensitive knowledge‑base data.

Generated by OpenCVE AI on August 4, 2026 at 11:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the AI ChatBot for WooCommerce plugin to version 4.8.4 or later, which adds proper authorization checks to the affected AJAX action.
  • Revoke any existing Gemini API keys that the plugin is using and create new keys, then reconfigure the plugin to use them—this limits the impact if an unauthorized request occurs before the patch is applied.
  • If the optional knowledge‑base retrieval feature is not essential, disable it or restrict access to authenticated administrators only; otherwise, ensure it is protected by the plugin’s updated access controls.

Generated by OpenCVE AI on August 4, 2026 at 11:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 02 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to retrieve indexed knowledge-base content.
Title ChatBot for eCommerce – WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_gemini_response
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-03T17:42:56.458Z

Reserved: 2026-07-09T11:52:44.105Z

Link: CVE-2026-15241

cve-icon Vulnrichment

Updated: 2026-08-03T17:42:52.432Z

cve-icon NVD

Status : Received

Published: 2026-08-02T06:16:37.100

Modified: 2026-08-03T18:16:35.483

Link: CVE-2026-15241

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T11:15:06Z

Weaknesses