Impact
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to stored cross‑site scripting through its "conversation" parameter. The flaw arises from insufficient input sanitization and output escaping. Attackers can inject arbitrary JavaScript that is persisted in the database and executed whenever a page containing the conversation data is loaded by a user.
Affected Systems
The vulnerability affects all releases of the quantumcloud WPBot plugin up to and including version 8.7.3. Hosts running any of these versions are susceptible; the flaw is isolated to the plugin and does not impact core WordPress components.
Risk and Exploitability
The base CVSS score of 7.2 places this flaw in the high‑severity category. Because the flaw does not require authentication and the public‑facing nonce is ineffective as an access‑control guard, the attack can be carried out by unauthenticated users. The EPSS score is not available, so the probability of exploitation cannot be quantified. The vulnerability is not yet listed in the CISA KEV catalog.
OpenCVE Enrichment