PT-2026-65450 · Quantumcloud · Wpbot – Ai Chatbot For Live Support

·

CVE-2026-16774

·

Published

2026-07-28

·

Updated

2026-07-28

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs send email() AJAX handler. This is due to the wpcs send email() function being registered on both wp ajax wpcs send email and wp ajax nopriv wpcs send email with no nonce verification, capability check, or rate limiting, while forwarding attacker-controlled recipient, subject, and body directly to wp mail(). This makes it possible for unauthenticated attackers to send arbitrary emails to any recipient from the site's domain, enabling spam, phishing, and abuse that can lead to the site's IP/domain being blacklisted.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16774

Affected Products

Wpbot – Ai Chatbot For Live Support