Impact
WPBot, a WordPress plugin, suffers from an authorization bypass (CWE‑284) because it does not enforce authentication or nonce checks on several AJAX actions that forward user prompts to its configured AI providers. This omission allows an attacker to trigger these actions unauthenticated, causing the plugin to consume the site’s AI service keys for arbitrary third‑party API calls, incurring costs to the site.
Affected Systems
The vulnerability affects installations of the WPBot WordPress plugin running any version earlier than 8.5.7. Any WordPress site that has this plugin configured and has not upgraded is potentially exposed, regardless of whether the plugin is publicly visible or restricted to logged‑in users.
Risk and Exploitability
Exploitation requires only the ability to send an unauthenticated AJAX request to the plugin’s exposed endpoints; based on the description, it is inferred that this request can be performed from any origin. The EPSS score is below 1%, indicating a low but nonzero likelihood of exploitation in the wild, and the CVSS score of 5.3 reflects a moderate severity. The vulnerability is not listed in the CISA KEV catalog. An attacker who successfully abuses the endpoint can accumulate significant charges on the site’s AI account, representing a moderate economic risk.
OpenCVE Enrichment