Stored Cross-Site Scripting in AI Chatbot & Workflow Automation Plugin by AIWU
CVE-2026-2955
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 May 2026
What is CVE-2026-2955?
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to inadequate sanitization of the 'X-Forwarded-For' header. This vulnerability allows unauthenticated attackers to inject malicious scripts into web pages that are subsequently executed when users access the manipulated content. Exploitation is limited by a 20-character storage cap; however, it still poses a risk to unsuspecting users.
Affected Version(s)
AI Chatbot & Workflow Automation by AIWU 0 <= 1.4.14