Missing Authorization Vulnerability in Chatbot Plugin for WordPress
CVE-2026-16774
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-16774?
The Chatbot plugin for WordPress has a vulnerability that allows unauthenticated users to exploit the wpcs_send_email() AJAX handler. This issue arises because the function can be invoked without nonce verification, capability checks, or rate limiting, providing attackers the ability to send arbitrary emails from the site's domain. This lack of security measures could lead to spam, phishing attempts, and other abuses, risking the site's reputation and potentially resulting in the IP or domain being blacklisted.
Affected Version(s)
WPBot β AI ChatBot for Live Support, Lead Generation, AI Services 0 <= 8.5.9