Description
The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI provider settings, allowing users with subscriber-level access to overwrite those settings, including the API key used for the WPBot WordPress plugin before 8.7.6's outgoing AI requests.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized configuration change via improper access control
Action: Patch
AI Analysis

Impact

The WPBot WordPress plugin prior to version 8.7.6 fails to verify user capabilities for an AJAX action that stores Claude AI provider settings. A user with subscriber-level access can submit this AJAX request, thereby overwriting the plugin’s configuration, including the API key used for outgoing AI requests. This allows an attacker to modify how the plugin interacts with the AI provider, potentially forcing the plugin to send malicious or expensive requests and unintentionally disclosing the API key to unauthorized parties. The core security consequence is a privilege escalation within the plugin, enabling configuration tampering and possible abuse of the AI service.

Affected Systems

WPBot plugin versions 8.7.2 through 8.7.5 installed on WordPress sites are affected. The plugin is referred to simply as WPBot, and no additional vendor details are provided. All mainstream WordPress installations that have not upgraded past 8.7.5 are vulnerable.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not currently listed in the CISA KEV catalog, indicating a low probability of widespread exploitation at present. Nevertheless, the attack vector is local: any authenticated WordPress user with the subscriber role can exploit the flaw by invoking the vulnerable AJAX endpoint. In environments where such users have broad access or where the endpoint is inadvertently exposed, the risk rises to moderate. The vulnerability’s severity is limited to configuration tampering; it does not directly enable arbitrary code execution or data exfiltration, but it can lead to resource abuse and accidental disclosure of sensitive API credentials.

Generated by OpenCVE AI on September 16, 2026 at 16:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WPBot plugin to version 8.7.6 or later to restore proper capability checks for the AJAX action.
  • If an immediate upgrade is not possible, restrict subscriber access to the affected AJAX endpoint by using a security plugin or access‑control rules that deny that capability.
  • After updating, regenerate the Claude AI provider API key to ensure any potentially compromised keys are replaced.

Generated by OpenCVE AI on September 16, 2026 at 16:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Wed, 16 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI provider settings, allowing users with subscriber-level access to overwrite those settings, including the API key used for the WPBot WordPress plugin before 8.7.6's outgoing AI requests.
Title WPBot 8.7.2 - 8.7.5 - Subscriber+ Claude AI Settings Update
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-16T06:00:17.359Z

Reserved: 2026-09-09T17:18:39.516Z

Link: CVE-2026-87959

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-16T06:16:35.610

Modified: 2026-09-16T20:25:29.240

Link: CVE-2026-87959

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T16:30:08Z

Weaknesses