WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

Explore WPBot – AI ChatBot for Live Support, Lead Generation, AI Services vulnerabilities across all versions. Currently tracking 42 known vulnerabilities, including severity, impact, and patch status.

01234567891027.01.2023Today27.01.20234.4ChatBot <= 4.3.0 - Authenticated (Admin+) Cross-Site Scripting CVSS 4.4 · 27.01.20235.4ChatBot <= 4.2.8 - Cross-Site Request Forgery to Stored Cross-Site Scripting and Settings Reset CVSS 5.4 · 27.01.202329.03.20235.4AI ChatBot <= 4.4.7 - Missing Authorization on openai_settings_option_callback CVSS 5.4 · 29.03.202312.04.20234.4AI ChatBot <= 4.4.9 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 12.04.20239.8ChatBot <= 4.4.6 - Unauthenticated PHP Object Injection via Cookies CVSS 9.8 · 12.04.20236.4ChatBot <= 4.4.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via openai_settings_option_callback CVSS 6.4 · 12.04.20236.5ChatBot <= 4.4.8 - Unauthenticated Stored Cross-Site Scripting in Admin Dashboard CVSS 6.5 · 12.04.202320.04.20236.1ChatBot <= 4.4.4 - Unauthenticated Stored Cross-Site Scripting via Cross-Site Request Forgery CVSS 6.1 · 20.04.202322.05.20234.4AI ChatBot <= 4.5.4 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 22.05.20234.4AI ChatBot <= 4.6.0 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 22.05.202325.05.20234.4AI ChatBot <= 4.5.5 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 25.05.202308.08.20234.4ChatBot 4.7.7 - Authenticated (Administrator+) Stored Cross-Site Scripting in Language Settings CVSS 4.4 · 08.08.20234.4ChatBot <= 4.7.7 - Authenticated (Administrator+) Stored Cross-Site Scripting in FAQ Builder CVSS 4.4 · 08.08.202303.10.20235.3ChatBot <= 4.7.8 - Cross-Site Request Forgery via qc_wp_latest_update_check CVSS 5.3 · 03.10.202311.10.20235.3AI ChatBot <= 4.8.9 - Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_user CVSS 5.3 · 11.10.20235.3AI ChatBot <= 4.8.9 and 4.9.2 - Missing Authorization on AJAX actions CVSS 5.3 · 11.10.20234.3AI ChatBot <= 4.8.9 and 4.9.2 - Cross-Site Request Forgery on AJAX actions CVSS 4.3 · 11.10.20239.6AI ChatBot <= 4.8.9 and 4.9.2 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_file CVSS 9.6 · 11.10.20239.6AI ChatBot <= 4.8.9 and 4.9.2- Authenticated (Subscriber+) Arbitrary File Deletion via qcld_openai_delete_training_file CVSS 9.6 · 11.10.20239.8AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_response CVSS 9.8 · 11.10.202301.11.20234.4ChatBot 4.8.6 - 4.9.6 - Authenticated (Administrator+) Stored Cross-Site Scripting in FAQ Builder CVSS 4.4 · 01.11.202323.11.20237.2ChatBot <= 4.7.8 - Authenticated (Administrator+) SQL Injection CVSS 7.2 · 23.11.202319.01.20249.8ChatBot <= 5.1.0 - Unauthenticated PHP Object Injection CVSS 9.8 · 19.01.202421.05.20245.0AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_upload_callback CVSS 5.0 · 21.05.20245.0AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_delete_callback CVSS 5.0 · 21.05.20245.0AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_list_callback CVSS 5.0 · 21.05.202416.07.20245.5AI ChatBot for WordPress – WPBot <= 5.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 5.5 · 16.07.202423.02.20258.8ChatBot <= 6.3.5 - Authenticated (Contributor+) Local File Inclusion CVSS 8.8 · 23.02.202503.03.20254.4AI ChatBot for WordPress – WPBot <= 6.2.3 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 03.03.202527.06.20255.4ChatBot <= 6.7.3 - Missing Authorization CVSS 5.4 · 27.06.202519.08.20254.4AI ChatBot for WordPress <= 7.1.0 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 19.08.202512.10.20255.3ChatBot <= 7.3.9 - Missing Authorization CVSS 5.3 · 12.10.202513.10.20254.3ChatBot <= 7.7.3 - Missing Authorization CVSS 4.3 · 13.10.202520.03.20267.5WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 7.7.9 - Unauthenticated SQL Injection CVSS 7.5 · 20.03.202623.04.20264.3WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 7.9.7 - Missing Authorization CVSS 4.3 · 23.04.202630.06.20267.2WPBot <= 8.4.9 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter CVSS 7.2 · 30.06.202601.07.20266.1WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 8.3.2 - Reflected Cross-Site Scripting CVSS 6.1 · 01.07.202606.07.20267.2WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 8.3.7 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 06.07.202615.07.20264.3WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Function CVSS 4.3 · 15.07.20265.3WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameter CVSS 5.3 · 15.07.202627.07.20265.3WPBot <= 8.5.9 - Missing Authorization to Unauthenticated Email Relay via wpcs_send_email AJAX Action CVSS 5.3 · 27.07.20265.3WPBot <= 8.5.9 - Unauthenticated Sensitive Information Exposure in 'wpbot_send_email_transcript' AJAX Action CVSS 5.3 · 27.07.2026

Strategic Overview

Avg CVSSMedium
5.9/ 10
Patch Coverage100%
Open

0

Fixed

42

Get automatic notifications for all WPBot – AI ChatBot for Live Support, Lead Generation, AI Services vulnerabilities before they are exploited.

Vulnerability Records

42 records
2026-07-27 23:30CVE-2026-16773
5.3
Medium
Wordfence PRISMYes
2026-07-27 23:29CVE-2026-16774
5.3
Medium
Wordfence PRISMYes
2026-07-15 19:50CVE-2026-15106
5.3
Medium
Wordfence PRISMYes
2026-07-15 19:49CVE-2026-15610
4.3
Medium
Wordfence PRISMYes
2026-07-06 00:00CVE-2026-57363
7.2
High
darooYes
2026-07-01 00:00CVE-2026-57362
6.1
Medium
Nguyen Dinh Hai (HaiND)Yes
2026-06-30 15:06CVE-2026-13731
7.2
High
Wordfence PRISMYes
2026-04-23 00:00CVE-2026-40788
4.3
Medium
Mehdi OuassouYes
2026-03-20 00:00CVE-2026-32499
7.5
High
Nguyen Ba KhanhYes
2025-10-13 00:00CVE-2025-62952
4.3
Medium
Legion HunterYes
Showing 1–10 of 42 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C