๐Ÿ” CVE Alert

CVE-2026-15241

UNKNOWN 0.0

ChatBot for eCommerce โ€“ WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_gemini_response

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to retrieve indexed knowledge-base content.

Vendor unknown
Product ai chatbot for woocommerce
Published Aug 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown ai chatbot for woocommerce

Be the first to know when new unknown vulnerabilities affecting unknown ai chatbot for woocommerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / AI ChatBot for WooCommerce
0 < 4.8.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/81ab9ecd-5d7b-4d10-b255-65af869c46e2/

Credits

Pedro Pinho WPScan