Missing Authorization Vulnerability in Chatbot Plugin for WordPress
CVE-2026-16774

5.3MEDIUM

What is CVE-2026-16774?

The Chatbot plugin for WordPress has a vulnerability that allows unauthenticated users to exploit the wpcs_send_email() AJAX handler. This issue arises because the function can be invoked without nonce verification, capability checks, or rate limiting, providing attackers the ability to send arbitrary emails from the site's domain. This lack of security measures could lead to spam, phishing attempts, and other abuses, risking the site's reputation and potentially resulting in the IP or domain being blacklisted.

Affected Version(s)

WPBot – AI ChatBot for Live Support, Lead Generation, AI Services 0 <= 8.5.9

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.