Extension WordPress

Vulnérabilités WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

Cette page rassemble les failles publiées pour WPBot – AI ChatBot for Live Support, Lead Generation, AI Services, leurs plages de versions affectées et les correctifs signalés dans la base locale.

40Vulnérabilités
5Critiques
40Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

40 fiches

CVE-2026-15106 Moyenne · 5,3
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

WPBot <= 8.5.6 – Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameter

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.5.6. This is due to the plugin not properly verifying that…

Versions affectées

*-8.5.6

Correctif

8.5.7

Publication

15/07/2026

CVE-2026-15610 Moyenne · 4,3
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

WPBot <= 8.5.6 – Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Function

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.5.6. This is due to the plugin not properly verifying that…

Versions affectées

*-8.5.6

Correctif

8.5.7

Publication

15/07/2026

CVE-2026-57363 Élevée · 7,2
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 8.3.7 – Unauthenticated Stored Cross-Site Scripting

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.3.7 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-8.3.7

Correctif

8.3.8

Publication

06/07/2026

CVE-2026-57362 Moyenne · 6,1
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 8.3.2 – Reflected Cross-Site Scripting

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 8.3.2 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-8.3.2

Correctif

8.3.3

Publication

01/07/2026

CVE-2026-13731 Élevée · 7,2
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

WPBot <= 8.4.9 – Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conversation' parameter in all versions up to, and including, 8.4.9 due to insufficient input sanitization…

Versions affectées

*-8.4.9

Correctif

8.5.0

Publication

30/06/2026

CVE-2026-40788 Moyenne · 4,3
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 7.9.7 – Missing Authorization

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.9.7. This makes…

Versions affectées

*-7.9.7

Correctif

7.9.9

Publication

23/04/2026

CVE-2026-32499 Élevée · 7,5
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 7.7.9 – Unauthenticated SQL Injection

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.7.9 due to insufficient escaping on the user supplied parameter and lack…

Versions affectées

*-7.7.9

Correctif

7.8.0

Publication

20/03/2026

CVE-2025-9111 Moyenne · 4,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot for WordPress <= 7.1.0 – Authenticated (Admin+) Stored Cross-Site Scripting

The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.0 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-7.0.0

Correctif

7.1.0

Publication

19/08/2025

CVE-2025-0329 Moyenne · 4,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot for WordPress – WPBot <= 6.2.3 – Authenticated (Admin+) Stored Cross-Site Scripting

The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.2.3 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-6.2.3

Correctif

6.2.4

Publication

03/03/2025

CVE-2025-26932 Élevée · 8,8
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot <= 6.3.5 – Authenticated (Contributor+) Local File Inclusion

The ChatBot plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.3.5. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the…

Versions affectées

*-6.3.5

Correctif

6.3.6

Publication

23/02/2025

CVE-2024-6669 Moyenne · 5,5
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot for WordPress – WPBot <= 5.5.7 – Authenticated (Administrator+) Stored Cross-Site Scripting

The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.5.7 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-5.5.7

Correctif

5.5.8

Publication

16/07/2024

CVE-2024-0453 Moyenne · 5,0
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 5.3.4 – Missing Authorization via openai_file_delete_callback

The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers,…

Versions affectées

*-5.3.4

Correctif

5.3.6

Publication

21/05/2024

CVE-2024-0452 Moyenne · 5,0
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 5.3.4 – Missing Authorization via openai_file_upload_callback

The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_upload_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers,…

Versions affectées

*-5.3.4

Correctif

5.3.6

Publication

21/05/2024

CVE-2024-0451 Moyenne · 5,0
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

AI ChatBot <= 5.3.4 – Missing Authorization via openai_file_list_callback

The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the openai_file_list_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers,…

Versions affectées

*-5.3.4

Correctif

5.3.6

Publication

21/05/2024

CVE-2024-22309 Critique · 9,8
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot <= 5.1.0 – Unauthenticated PHP Object Injection

The ChatBot with AI plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1.0 via deserialization of untrusted input via the last_five_prompt cookies. This makes it possible for unauthenticated attackers to…

Versions affectées

*-5.1.0

Correctif

5.1.1

Publication

19/01/2024

CVE-2023-5606 Moyenne · 4,4
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

ChatBot 4.8.6 – 4.9.6 – Authenticated (Administrator+) Stored Cross-Site Scripting in FAQ Builder

The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions 4.8.6 through 4.9.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and…

Versions affectées

4.8.6-4.9.6

Correctif

4.9.7

Publication

01/11/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités