PT-2026-65450 · WordPress · Chatbot For Wordpress
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Chatbot for WordPress versions prior to 8.6.0
Description
The software contains a missing authorization flaw in the
wpcs send email() AJAX handler. The wpcs send email() function is registered on both wp ajax wpcs send email and wp ajax nopriv wpcs send email without nonce verification, capability checks, or rate limiting. This allows unauthenticated attackers to send arbitrary emails to any recipient from the site's domain by controlling the recipient, subject, and body parameters forwarded to wp mail(), which can result in the site's IP or domain being blacklisted due to spam or phishing.Recommendations
Update to a version newer than 8.5.9.
As a temporary workaround, restrict access to the
wpcs send email() function until a patch is applied.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chatbot For Wordpress