CVE-2026-87916
WPBot 8.4.9 - 8.5.9 - Unauthenticated Chat Visitor PII Disclosure
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every chat visitor by requesting a wide date range.
| Vendor | unknown |
| Product | wpbot |
| Published | Sep 12, 2026 |
| Last Updated | Sep 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wpbot
Be the first to know when new medium vulnerabilities affecting unknown wpbot are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WPBot
8.4.9 < 8.6.0
References
Credits
Seongwon Lee WPScan