Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

WPBot – AI ChatBot for Live Support, Lead Generation, AI Services — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in WPBot – AI ChatBot for Live Support, Lead Generation, AI Services, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities associated with the product WPBot – AI ChatBot for Live Support, Lead Generation, AI Services, classified under the general weakness type of missing or improper input validation. It collects a comprehensive set of vulnerability records and security advisories covering the time range from the initial public release of the software through its most recent maintenance updates. Readers can use this resource to track the vendor's published security notices, analyze the specific class of coding defects present in the codebase, and review the complete historical log of discovered security flaws. The aggregation focuses on factual reporting of technical defects without promotional commentary or marketing language. Specific Common Vulnerabilities and Exposures (CVE) identifiers are not listed in this introductory summary, but the full dataset contains detailed records for each entry. This section serves as a central reference point for security professionals and system administrators who need to assess the risk profile of the WPBot platform. By examining the aggregated data, stakeholders can identify recurring patterns in the weakness types, evaluate the severity of each reported issue, and determine the necessary patches or mitigations. The information presented here supports proactive security planning and compliance verification for organizations relying on automated customer support and lead generation tools.

Vendor: quantumcloud

CVE ID Title CVSS Severity Published
CVE-2026-83593 WPBot <= 8.7.3 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter CWE-79 7.2 High 2026-09-09
CVE-2026-16773 WPBot <= 8.5.9 - Unauthenticated Sensitive Information Exposure in 'wpbot_send_email_transcript' AJAX Action CWE-200 5.3 Medium 2026-07-28
CVE-2026-16774 WPBot <= 8.5.9 - Missing Authorization to Unauthenticated Email Relay via wpcs_send_email AJAX Action CWE-862 5.3 Medium 2026-07-28
CVE-2026-15610 WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Function CWE-862 4.3 Medium 2026-07-16
CVE-2026-15106 WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameter CWE-862 5.3 Medium 2026-07-16
CVE-2026-13731 WPBot <= 8.4.9 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter CWE-79 7.2 High 2026-07-01
CVE-2024-6669 AI ChatBot for WordPress – WPBot <= 5.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting CWE-79 5.5 Medium 2024-07-17
CVE-2024-0453 AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_delete_callback CWE-284 5.0 Medium 2024-05-22
CVE-2024-0451 AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_list_callback CWE-284 5.0 Medium 2024-05-22
CVE-2024-0452 AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_upload_callback CWE-284 5.0 Medium 2024-05-22
CVE-2023-5533 AI ChatBot <= 4.8.9 and 4.9.2 - Missing Authorization on AJAX actions CWE-862 5.3 Medium 2023-10-20
CVE-2023-5534 AI ChatBot <= 4.8.9 and 4.9.2 - Cross-Site Request Forgery on AJAX actions CWE-352 4.3 Medium 2023-10-20
CVE-2023-5254 AI ChatBot <= 4.8.9 - Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_user CWE-200 5.3 Medium 2023-10-19
CVE-2023-5212 AI ChatBot <= 4.8.9 and 4.9.2- Authenticated (Subscriber+) Arbitrary File Deletion via qcld_openai_delete_training_file CWE-22 9.6 Critical 2023-10-19
CVE-2023-5241 AI ChatBot <= 4.8.9 and 4.9.2 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_file CWE-22 9.6 Critical 2023-10-19
CVE-2023-5204 AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_response CWE-89 9.8 Critical 2023-10-19

All 16 known CVE vulnerabilities affecting WPBot – AI ChatBot for Live Support, Lead Generation, AI Services with full Chinese analysis, references, and POCs where available.