Executive brief
WPBot Pro is a chatbot plugin for WordPress websites used to automate customer interactions. A security flaw allows users with basic 'Subscriber' accounts to delete arbitrary files on the web server. This can lead to a complete site failure if critical system files are removed, potentially causing significant downtime and operational disruption.
Technical details
The WPBot Pro plugin for WordPress (versions up to and including 13.6.5) contains an arbitrary file deletion vulnerability. The flaw is rooted in improper limitation of a pathname to a restricted directory (CWE-22), commonly known as path traversal. An attacker with Subscriber-level authentication can exploit this by sending crafted requests to delete files outside of the intended directory. Successful exploitation can lead to a Denial of Service (DoS) by deleting critical WordPress core files or configuration files. As of the advisory date, no official patch has been released, though third-party mitigation rules are available.
Affected products
- QuantumCloud WPBot Pro Wordpress Chatbot <= 13.6.5
Timeline
- 2025-04-19: other: Vulnerability reported by researcher
- 2025-05-19: advisory: Patchstack advisory published
- 2026-06-17: disclosed: NVD publication date