Description
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and associated user PII — including names, email addresses, and phone numbers — stored in the wpbot_user and wpbot_conversation tables to an attacker-controlled email address.
Published: 2026-07-28
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WPBot plugin for WordPress contains a flaw that allows anyone to trigger the wpbot_send_email_transcript_free AJAX action without authentication. This action sends complete chat transcripts, along with personal identifying information such as names, email addresses, and phone numbers stored in the wpbot_user and wpbot_conversation tables, to a user‑specified email address. The result is a confidentiality breach that exposes user‑generated content and PII to an attacker.

Affected Systems

All installations of the quantumcloud WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin with version 8.5.9 or earlier are vulnerable. No specific sub‑versions are listed, but the issue applies to all releases up to and including 8.5.9. Higher versions proprietary or later releases are not indicated as affected.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score of < 1% demonstrates a very low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Because an attacker does not need to authenticate, the likely attack vector is a simple unauthenticated HTTP request to the wpbot_send_email_transcript_free endpoint, allowing the attacker to specify an arbitrary destination email address for exfiltration.

Generated by OpenCVE AI on August 3, 2026 at 15:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WPBot to the latest available version where the wpbot_send_email_transcript action is fixed or removed.
  • Block or restrict the wpbot_send_email_transcript_free AJAX endpoint for unauthenticated users by adding a firewall rule, .htaccess restriction, or security plugin configuration.
  • Enforce mail server authentication and restrict outbound mail to trusted destinations to prevent unintended email delivery.

Generated by OpenCVE AI on August 3, 2026 at 15:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Quantumcloud
Quantumcloud wpbot – Ai Chatbot For Live Support, Lead Generation, Ai Services
Wordpress
Wordpress wordpress
Vendors & Products Quantumcloud
Quantumcloud wpbot – Ai Chatbot For Live Support, Lead Generation, Ai Services
Wordpress
Wordpress wordpress

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and associated user PII — including names, email addresses, and phone numbers — stored in the wpbot_user and wpbot_conversation tables to an attacker-controlled email address.
Title WPBot <= 8.5.9 - Unauthenticated Sensitive Information Exposure in 'wpbot_send_email_transcript' AJAX Action
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Quantumcloud Wpbot – Ai Chatbot For Live Support, Lead Generation, Ai Services
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-28T19:18:32.377Z

Reserved: 2026-07-23T17:08:39.007Z

Link: CVE-2026-16773

cve-icon Vulnrichment

Updated: 2026-07-28T19:18:28.115Z

cve-icon NVD

Status : Deferred

Published: 2026-07-28T12:16:35.900

Modified: 2026-07-28T20:17:24.137

Link: CVE-2026-16773

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor