PT-2026-65450 · WordPress · Chatbot For Wordpress

·

CVE-2026-16774

·

Published

2026-07-28

·

Updated

2026-07-28

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Chatbot for WordPress versions prior to 8.6.0
Description The software contains a missing authorization flaw in the wpcs send email() AJAX handler. The wpcs send email() function is registered on both wp ajax wpcs send email and wp ajax nopriv wpcs send email without nonce verification, capability checks, or rate limiting. This allows unauthenticated attackers to send arbitrary emails to any recipient from the site's domain by controlling the recipient, subject, and body parameters forwarded to wp mail(), which can result in the site's IP or domain being blacklisted due to spam or phishing.
Recommendations Update to a version newer than 8.5.9. As a temporary workaround, restrict access to the wpcs send email() function until a patch is applied.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16774

Affected Products

Chatbot For Wordpress