WordPress · Wpbot · CVE-2026-15610
**Name of the Vulnerable Software and Affected Versions**
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services versions prior to 8.5.7
**Description**
An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Authenticated attackers with subscriber-level access or higher can trigger the arbitrary re-embedding of stored RAG (Retrieval-Augmented Generation) documents. This process modifies the `rag documents` table and results in the unauthorized consumption of the site owner's paid third-party AI API credits from providers such as OpenAI, Gemini, OpenRouter, or xAI.
**Recommendations**
Update WPBot – AI ChatBot for Live Support, Lead Generation, AI Services to version 8.5.7 or later.