PT-2026-65450 · Quantumcloud · Wpbot – Ai Chatbot For Live Support

·

CVE-2026-16774

·

Publicado

2026-07-28

·

Atualizado

2026-07-28

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs send email() AJAX handler. This is due to the wpcs send email() function being registered on both wp ajax wpcs send email and wp ajax nopriv wpcs send email with no nonce verification, capability check, or rate limiting, while forwarding attacker-controlled recipient, subject, and body directly to wp mail(). This makes it possible for unauthenticated attackers to send arbitrary emails to any recipient from the site's domain, enabling spam, phishing, and abuse that can lead to the site's IP/domain being blacklisted.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-16774

Produtos afetados

Wpbot – Ai Chatbot For Live Support