Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

WPBot – AI ChatBot for Live Support, Lead Generation, AI Services — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in WPBot – AI ChatBot for Live Support, Lead Generation, AI Services, with AI-generated Chinese analysis, references, and POCs.

WPBot is a WordPress plugin developed by a third-party vendor that aggregates known weaknesses related to its AI chatbot, live support, and lead generation functionalities. This page collects details on security flaws identified within the software, ranging from version control discrepancies to potential injection vectors in its AI service integrations. The data spans historical releases up to the most recent updates, providing a comprehensive view of the product's security posture over time. Visitors can use this resource to track vendor advisories as they are published, helping administrators stay informed about critical patches and configuration changes. By examining the aggregated list, users can better understand the specific weakness classes affecting this tool, such as cross-site scripting or authentication bypasses, and assess the relevance to their own deployment environments. Additionally, the page serves as a reference for looking up a product's vulnerability history, allowing security teams to analyze trends in bug disclosures and identify recurring patterns in code or logic errors. This information supports informed decision-making regarding plugin updates, risk mitigation strategies, and compliance requirements for sites using WPBot for customer interaction and data collection.

Vendor: quantumcloud

CVE IDTitleCVSSSeverityPublished
CVE-2026-16773 WPBot <= 8.5.9 - Unauthenticated Sensitive Information Exposure in 'wpbot_send_email_transcript' AJAX Action CWE-200 5.3 Medium2026-07-28
CVE-2026-16774 WPBot <= 8.5.9 - Missing Authorization to Unauthenticated Email Relay via wpcs_send_email AJAX Action CWE-862 5.3 Medium2026-07-28
CVE-2026-15610 WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Function CWE-862 4.3 Medium2026-07-16
CVE-2026-15106 WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameter CWE-862 5.3 Medium2026-07-16
CVE-2026-13731 WPBot <= 8.4.9 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter CWE-79 7.2 High2026-07-01
CVE-2024-6669 AI ChatBot for WordPress – WPBot <= 5.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting CWE-79 5.5 Medium2024-07-17
CVE-2024-0453 AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_delete_callback CWE-284 5.0 Medium2024-05-22
CVE-2024-0451 AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_list_callback CWE-284 5.0 Medium2024-05-22
CVE-2024-0452 AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_upload_callback CWE-284 5.0 Medium2024-05-22
CVE-2023-5533 AI ChatBot <= 4.8.9 and 4.9.2 - Missing Authorization on AJAX actions CWE-862 5.3 Medium2023-10-20
CVE-2023-5534 AI ChatBot <= 4.8.9 and 4.9.2 - Cross-Site Request Forgery on AJAX actions CWE-352 4.3 Medium2023-10-20
CVE-2023-5254 AI ChatBot <= 4.8.9 - Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_user CWE-200 5.3 Medium2023-10-19
CVE-2023-5212 AI ChatBot <= 4.8.9 and 4.9.2- Authenticated (Subscriber+) Arbitrary File Deletion via qcld_openai_delete_training_file CWE-22 9.6 Critical2023-10-19
CVE-2023-5241 AI ChatBot <= 4.8.9 and 4.9.2 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_file CWE-22 9.6 Critical2023-10-19
CVE-2023-5204 AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_response CWE-89 9.8 Critical2023-10-19

All 15 known CVE vulnerabilities affecting WPBot – AI ChatBot for Live Support, Lead Generation, AI Services with full Chinese analysis, references, and POCs where available.