Description
The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI provider settings, allowing users with subscriber-level access to overwrite those settings, including the API key used for the WPBot WordPress plugin before 8.7.6's outgoing AI requests.
Published: 2026-09-16
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized configuration change via improper access control
Action: Patch
AI Analysis

Impact

The WPBot WordPress plugin prior to version 8.7.6 fails to verify user capabilities for an AJAX action that stores Claude AI provider settings. A user with subscriber-level access can submit this AJAX request, thereby overwriting the plugin’s configuration, including the API key used for outgoing AI requests. This allows an attacker to modify how the plugin interacts with the AI provider, potentially forcing the plugin to send malicious or expensive requests and unintentionally disclosing the API key to unauthorized parties. The core security consequence is a privilege escalation within the plugin, enabling configuration tampering and possible abuse of the AI service.

Affected Systems

WPBot plugin versions 8.7.2 through 8.7.5 installed on WordPress sites are affected. The plugin is referred to simply as WPBot, and no additional vendor details are provided. All mainstream WordPress installations that have not upgraded past 8.7.5 are vulnerable.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not currently listed in the CISA KEV catalog, indicating a low probability of widespread exploitation at present. Nevertheless, the attack vector is local: any authenticated WordPress user with the subscriber role can exploit the flaw by invoking the vulnerable AJAX endpoint. In environments where such users have broad access or where the endpoint is inadvertently exposed, the risk rises to moderate. The vulnerability’s severity is limited to configuration tampering; it does not directly enable arbitrary code execution or data exfiltration, but it can lead to resource abuse and accidental disclosure of sensitive API credentials.

Generated by OpenCVE AI on September 18, 2026 at 10:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the WPBot plugin to version 8.7.6 or later to restore proper capability checks for the AJAX action.
  • If an immediate upgrade is not possible, restrict subscriber access to the affected AJAX endpoint by using a security plugin or access‑control rules that deny that capability.
  • After updating, regenerate the Claude AI provider API key to ensure any potentially compromised keys are replaced.

Generated by OpenCVE AI on September 18, 2026 at 10:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Wed, 16 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI provider settings, allowing users with subscriber-level access to overwrite those settings, including the API key used for the WPBot WordPress plugin before 8.7.6's outgoing AI requests.
Title WPBot 8.7.2 - 8.7.5 - Subscriber+ Claude AI Settings Update
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:32:13.415Z

Reserved: 2026-09-09T17:18:39.516Z

Link: CVE-2026-87959

cve-icon Vulnrichment

Updated: 2026-09-17T12:14:47.465Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T06:16:35.610

Modified: 2026-09-17T13:16:57.220

Link: CVE-2026-87959

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:45:06Z

Weaknesses