Description
The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attackers to make those third-party API calls, and consume the associated cost, using the site's own configured API keys.
Published: 2026-09-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized API usage and cost consumption
Action: Immediate Patch
AI Analysis

Impact

WPBot, a WordPress plugin, suffers from an authorization bypass (CWE‑284) because it does not enforce authentication or nonce checks on several AJAX actions that forward user prompts to its configured AI providers. This omission allows an attacker to trigger these actions unauthenticated, causing the plugin to consume the site’s AI service keys for arbitrary third‑party API calls, incurring costs to the site.

Affected Systems

The vulnerability affects installations of the WPBot WordPress plugin running any version earlier than 8.5.7. Any WordPress site that has this plugin configured and has not upgraded is potentially exposed, regardless of whether the plugin is publicly visible or restricted to logged‑in users.

Risk and Exploitability

Exploitation requires only the ability to send an unauthenticated AJAX request to the plugin’s exposed endpoints; based on the description, it is inferred that this request can be performed from any origin. The EPSS score is below 1%, indicating a low but nonzero likelihood of exploitation in the wild, and the CVSS score of 5.3 reflects a moderate severity. The vulnerability is not listed in the CISA KEV catalog. An attacker who successfully abuses the endpoint can accumulate significant charges on the site’s AI account, representing a moderate economic risk.

Generated by OpenCVE AI on September 15, 2026 at 18:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WPBot to version 8.5.7 or later to restore proper authorization checks on AJAX actions.
  • If an upgrade is not feasible immediately, block or limit the vulnerable AJAX endpoints to authenticated users only using a web‑application firewall or access‑control rules.
  • Revoke or rotate any configured AI provider API keys to reduce the monetary impact of accidental or malicious usage.

Generated by OpenCVE AI on September 15, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpbot
Wpbot wpot
Vendors & Products Wordpress
Wordpress wordpress
Wpbot
Wpbot wpot

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attackers to make those third-party API calls, and consume the associated cost, using the site's own configured API keys.
Title WPBot < 8.5.7 - Unauthenticated AI Provider API Abuse via Multiple AJAX Actions
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:28:19.145Z

Reserved: 2026-09-09T15:57:18.363Z

Link: CVE-2026-87918

cve-icon Vulnrichment

Updated: 2026-09-12T15:14:33.227Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:28.430

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-87918

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:00:15Z

Weaknesses