CVE-2026-14189
WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search.
| Vendor | unknown |
| Product | wpbot |
| Published | Jul 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wpbot
Be the first to know when new unknown vulnerabilities affecting unknown wpbot are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WPBot
0 < 8.5.2
References
Credits
Mustafa Ahmed WPScan