Arbitrary File Deletion Vulnerability in WPBot Pro WordPress Chatbot Plugin
CVE-2025-3812
8.1HIGH
What is CVE-2025-3812?
The WPBot Pro plugin for WordPress has a vulnerability allowing authenticated users with Subscriber access or higher to delete arbitrary files from the server. This is due to inadequate validation of file paths in the qcld_openai_delete_training_file() function. If exploited, this vulnerability could result in the deletion of critical files, such as wp-config.php, potentially leading to remote code execution and severe security breaches.
Affected Version(s)
WPBot Pro Wordpress Chatbot * <= 13.6.2