WPBot 8.4.9 - 8.5.9 - Unauthenticated Chat Visitor PII Disclosure
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.3%
exploitation probability
0.3%top 74% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every chat visitor by requesting a wide date range.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
Unknown · WPBotpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/31d65e66-10b1-467a-8b20-ecf4880359e0/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.