quantumcloud wpbot是quantumcloud个人开发者开源的一款WordPress聊天机器人。 QuantumCloud WPBot 8.4.9及之前版本存在跨站脚本漏洞,该漏洞源于输入清理和输出转义不足,通过'conversation'参数存在存储型跨站脚本漏洞,可能导致未经身份验证的攻击者在页面中注入任意Web脚本,当用户访问被注入的页面时即会执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| quantumcloud | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | ≤ 8.4.9 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| quantumcloud | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | 0 ~ 8.4.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WPBot <= 8.4.9 is vulnerable to stored cross-site scripting via the conversation parameter in the qcld_wb_chatbot_conversation_save AJAX action. The AJAX nonce (qcsecretbotnonceval123qc) is publicly emitted on every frontend page via wp_localize_script under the ajax_nonce key, making it freely obtainable by unauthenticated visitors. The conversation parameter is saved to the database without sanitization and rendered unsanitized in the admin chat session view, causing stored XSS that executes when an administrator views saved chat sessions. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-13731.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet