← WordPress Vulnerabilities
WordPress security by component

WPBot

WPBot is a WordPress component with 17 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: wpbot

CVE-2026-14189: WPBot administrator field identifiers permit SQL injection

WPBot before 8.5.2 places administrator-configured field identifiers into a database query without safely constraining them. A malicious or compromised administrator can store an SQL expression in the configuration, which is executed when a visitor triggers the affected search flow and can expose or alter database content. The CNA record does not identify the configuration field, search action, request parameter or query function.

PublishedJul 27, 2026
Known safe version8.5.2
Safe version
Jul 27, 2026 CVE-2026-14189
WPBot administrator field identifiers permit SQL injection
WPBot before 8.5.2 places administrator-configured field identifiers into a database query without safely constraining them. A malicious or compromised administrator can store an SQL expression in the configuration, which is executed when a visitor triggers the affected search flow and can expose or alter database content. The CNA record does not identify the configuration field, search action, request parameter or query function.
8.5.2
CVE3.8
NVDPending
Jul 21, 2026 CVE-2026-14185
WPBot: A security weakness
WPBot is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 8.2.0.
8.2.0
CVE4.3
NVDPending
Sep 09, 2025 CVE-2025-9111
AI ChatBot for WordPress: Cross-site scripting
AI ChatBot for WordPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE3.5
NVDPending
May 15, 2025 CVE-2025-0329
AI ChatBot for WordPress: Cross-site scripting
AI ChatBot for WordPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Nov 02, 2023 CVE-2023-5606
Wpbot: Cross-site scripting
Wpbot is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Oct 20, 2023 CVE-2023-5534
AI ChatBot: Cross-site request forgery
AI ChatBot is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD5.4
Oct 20, 2023 CVE-2023-5533
AI ChatBot: A security weakness
AI ChatBot is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD9.8
Sep 04, 2023 CVE-2023-4254
AI ChatBot: Cross-site scripting
AI ChatBot is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Sep 04, 2023 CVE-2023-4253
AI ChatBot: Cross-site scripting
AI ChatBot is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jul 10, 2023 CVE-2023-3175
AI ChatBot: Cross-site scripting
AI ChatBot is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jun 19, 2023 CVE-2023-2811
AI ChatBot: Cross-site scripting
AI ChatBot is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jun 19, 2023 CVE-2023-2742
AI ChatBot: Cross-site scripting
AI ChatBot is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
May 08, 2023 CVE-2023-1660
AI ChatBot: Cross-site scripting
AI ChatBot is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
May 08, 2023 CVE-2023-1651
AI ChatBot: Cross-site scripting
AI ChatBot is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
May 08, 2023 CVE-2023-1650
AI ChatBot: Code execution
AI ChatBot is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVD9.8
May 08, 2023 CVE-2023-1649
AI ChatBot: Cross-site scripting
AI ChatBot is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
May 08, 2023 CVE-2023-1011
AI ChatBot: Cross-site scripting
AI ChatBot is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1