Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.This issue affects ChatBot: from n/a through <= 8.3.7.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw where input provided to the QuantumCloud ChatBot plugin is saved in the database without proper neutralization and then rendered in web pages viewed by other users. Attackers can embed malicious scripts that execute in the browsers of anyone who accesses the affected page, potentially hijacking user sessions, defacing content, or exfiltrating data presented on the site. This weakness is identified as CWE‑79, Improper Neutralization of Input During Web Page Generation.

Affected Systems

QuantumCloud’s ChatBot WordPress plugin is affected in all releases up through version 8.3.7. No earlier version boundary is specified, so any installation of the plugin that is equal to or older than 8.3.7 is vulnerable. The plugin operates within standard WordPress installations and stores user‑supplied content in the database.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, while the EPSS score is below 1%, suggesting a low probability of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is through the plugin’s web interface; an attacker only needs the ability to submit data that will be stored and later rendered, without requiring administrative privileges.

Generated by OpenCVE AI on July 31, 2026 at 12:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install any available update to the QuantumCloud ChatBot plugin that is newer than version 8.3.7 and that removes the XSS flaw, as noted in vendor release documentation.
  • If an update is not available or cannot be applied immediately, temporarily disable or delete the ChatBot plugin to prevent malicious scripts from being stored and served.
  • While the vulnerability remains, apply input sanitization and output escaping to all data managed by the plugin, ensuring that stored content is properly encoded before rendering.

Generated by OpenCVE AI on July 31, 2026 at 12:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Quantumcloud
Quantumcloud chatbot
Wordpress
Wordpress wordpress
Vendors & Products Quantumcloud
Quantumcloud chatbot
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.This issue affects ChatBot: from n/a through <= 8.3.7.
Title WordPress ChatBot plugin <= 8.3.7 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Quantumcloud Chatbot
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:52:47.958Z

Reserved: 2026-06-24T12:45:46.645Z

Link: CVE-2026-57363

cve-icon Vulnrichment

Updated: 2026-07-13T13:52:44.703Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')