Impact
The WPBot plugin for WordPress contains a flaw that allows anyone to trigger the wpbot_send_email_transcript_free AJAX action without authentication. This action sends complete chat transcripts, along with personal identifying information such as names, email addresses, and phone numbers stored in the wpbot_user and wpbot_conversation tables, to a user‑specified email address. The result is a confidentiality breach that exposes user‑generated content and PII to an attacker.
Affected Systems
All installations of the quantumcloud WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin with version 8.5.9 or earlier are vulnerable. No specific sub‑versions are listed, but the issue applies to all releases up to and including 8.5.9. Higher versions proprietary or later releases are not indicated as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of < 1% demonstrates a very low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Because an attacker does not need to authenticate, the likely attack vector is a simple unauthenticated HTTP request to the wpbot_send_email_transcript_free endpoint, allowing the attacker to specify an arbitrary destination email address for exfiltration.
OpenCVE Enrichment