Description
Unauthenticated Cross Site Scripting (XSS) in ChatBot <= 8.3.2 versions.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated reflected cross‑site scripting flaw exists in the WordPress ChatBot plugin through version 8.3.2. The flaw permits an attacker to inject arbitrary JavaScript into user‑controlled input that is subsequently displayed by the plugin without proper sanitization, aligning with CWE‑79. Successful exploitation allows the execution of attacker‑supplied code in the context of a visitor’s browser, which can lead to session hijacking, data theft, or site defacement.

Affected Systems

QuantumCloud’s ChatBot plug‑in bundled with WordPress that has installed the ChatBot plugin version 8.3.2 or earlier is vulnerable and should determine the exact version installed to confirm exposure.

Risk and Exploitability

The CVSS score of 7.1 indicates medium‑to‑high risk, and the EPSS score of < 1% suggests a low but non‑zero probability of exploitation today. Based on the description, it is inferred that the attack vector is remote delivery of a crafted payload via a URL or form field any site visitor. The flaw is not listed in the CISA KEV catalog, yet its straightforward attack surface and potential for wide impact warrant prompt remediation.

Generated by OpenCVE AI on July 21, 2026 at 11:48 UTC.

Remediation

Vendor Solution

Update the WordPress ChatBot Plugin to the latest available version (at least 8.3.3).


OpenCVE Recommended Actions

  • Update the WordPress ChatBot Plugin to version 8.3.3 or later.
  • Verify that all user‑supplied input is properly sanitized and output encoded to prevent reflected XSS, following best practices for CWE‑79.
  • Conduct a comprehensive scan of the site for reflected XSS vulnerabilities.
  • If the patch cannot be applied immediately, disable or remove the ChatBot plugin to neutralize the threat.

Generated by OpenCVE AI on July 21, 2026 at 11:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Quantumcloud
Quantumcloud chatbot
Wordpress
Wordpress wordpress
Vendors & Products Quantumcloud
Quantumcloud chatbot
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in ChatBot <= 8.3.2 versions.
Title WordPress ChatBot plugin <= 8.3.2 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Quantumcloud Chatbot
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T19:44:09.312Z

Reserved: 2026-06-24T12:45:46.645Z

Link: CVE-2026-57362

cve-icon Vulnrichment

Updated: 2026-07-02T19:44:04.686Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')