PT-2026-61838 · WordPress · Wpbot
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WPBot WordPress plugin versions prior to 8.2.0
Description
An issue exists in a retrieval-augmented-generation (RAG) settings handler where the software fails to perform a capability or nonce check. This allows authenticated users with subscriber-level access to modify the plugin configuration. A nonce is a unique token used to protect against cross-site request forgery (CSRF) attacks.
Recommendations
Update the WPBot WordPress plugin to version 8.2.0 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpbot