CVE-2026-15241
ChatBot for eCommerce โ WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_gemini_response
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to retrieve indexed knowledge-base content.
| Vendor | unknown |
| Product | ai chatbot for woocommerce |
| Published | Aug 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown ai chatbot for woocommerce
Be the first to know when new unknown vulnerabilities affecting unknown ai chatbot for woocommerce are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / AI ChatBot for WooCommerce
0 < 4.8.4
References
Credits
Pedro Pinho WPScan