← back
CVE-2026-87916mediumCWE-200

WPBot 8.4.9 - 8.5.9 - Unauthenticated Chat Visitor PII Disclosure

33Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 5.3epss 0.3%
exploitation probability
0.3%top 74% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every chat visitor by requesting a wide date range.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
Unknown · WPBot
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.