Impact
The WPBot WordPress plugin prior to version 8.7.6 fails to verify user capabilities for an AJAX action that stores Claude AI provider settings. A user with subscriber-level access can submit this AJAX request, thereby overwriting the plugin’s configuration, including the API key used for outgoing AI requests. This allows an attacker to modify how the plugin interacts with the AI provider, potentially forcing the plugin to send malicious or expensive requests and unintentionally disclosing the API key to unauthorized parties. The core security consequence is a privilege escalation within the plugin, enabling configuration tampering and possible abuse of the AI service.
Affected Systems
WPBot plugin versions 8.7.2 through 8.7.5 installed on WordPress sites are affected. The plugin is referred to simply as WPBot, and no additional vendor details are provided. All mainstream WordPress installations that have not upgraded past 8.7.5 are vulnerable.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not currently listed in the CISA KEV catalog, indicating a low probability of widespread exploitation at present. Nevertheless, the attack vector is local: any authenticated WordPress user with the subscriber role can exploit the flaw by invoking the vulnerable AJAX endpoint. In environments where such users have broad access or where the endpoint is inadvertently exposed, the risk rises to moderate. The vulnerability’s severity is limited to configuration tampering; it does not directly enable arbitrary code execution or data exfiltration, but it can lead to resource abuse and accidental disclosure of sensitive API credentials.
OpenCVE Enrichment