Typebot
Typebot has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2024; all 2 are fixed as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for Typebot has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Typebot is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2024-38757Typebot <= 3.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Typebot
Author
Baptiste
Collect 4x more responses with conversational apps using Typebot. 👉 Build beautiful conversational apps and easily embed them in your WordPress site. 👉 Typebot helps you publish chat apps that feel native to your product and it provides the best experience for your users. 👉 With Typebot, you collect the answer as soon as the user answers the first question. You get to know exactly when the user tends to drop your form. This plugin relies on Typebot which is a tool that allows you to create conversational forms and directly integrate them on your WordPress site. 💁♂️ More information about Typebot: https://www.typebot.io/ 👨🏼💻 How Typebot handles collected data: https://www.typebot.io/privacy-policy Short Description Create advanced chat experiences without coding
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C