Executive brief
A vulnerability in the WPBot AI ChatBot plugin for WordPress allows users with administrative privileges to inject malicious database commands. While the initial setup requires administrative access, the malicious code is triggered later when a regular visitor performs a search on the website. This could lead to unauthorized access to sensitive data or disruption of the website's database operations.
Technical details
A second-order SQL injection vulnerability exists in the WPBot AI ChatBot plugin due to insufficient validation of the 'qc_bot_str_fields' parameter within the 'Simple Text Responses' settings. An authenticated administrator can save a crafted column name containing SQL commands. This payload is subsequently executed in the context of a database query when an unauthenticated visitor triggers the 'wpbo_search_response' AJAX action. The vulnerability allows for time-based blind SQL injection. The issue is fixed in version 8.5.2.
Affected products
- Unknown WPBot AI ChatBot < 8.5.2
Timeline
- 2026-07-06: disclosed: Publicly published by WPScan
- 2026-07-27: advisory: NVD published date