Executive brief
WPBot is a WordPress plugin used to provide AI-driven customer support and lead generation through a website chatbot. A security flaw allows unauthorized individuals to delete chat history and conversation logs without needing to log in. This could result in the loss of valuable customer interaction data and lead generation records, potentially impacting business operations and customer service tracking.
Technical details
The WPBot plugin for WordPress (versions up to 8.5.6) contains a missing authorization vulnerability (CWE-862) within its chat session management logic. Specifically, the plugin fails to validate the authorization of users attempting to perform deletion actions in the wpbot-chat-sessions.php component. An unauthenticated attacker can exploit this by sending a crafted request with a specific 'userid' value to delete records from the 'wpbot_user' and 'wpbot_conversation' database tables. This allows for the remote, unauthorized deletion of chat history and session metadata. A fix was introduced in versions following 8.5.6.
Affected products
- QuantumCloud WPBot – AI ChatBot for Live Support, Lead Generation, AI Services up to, and including, 8.5.6
Timeline
- 2026-07-16: disclosed
- 2026-07-16: advisory
References
- https://plugins.trac.wordpress.org/browser/chatbot/tags/8.4.9/includes/chat-sessions/wpbot-chat-sessions.php
- https://plugins.trac.wordpress.org/browser/chatbot/tags/8.4.9/includes/chat-sessions/wpbot-chat-sessions.php
- https://plugins.trac.wordpress.org/browser/chatbot/tags/8.4.9/includes/chat-sessions/wpbot-chat-sessions.php
- https://plugins.trac.wordpress.org/browser/chatbot/tags/8.5.0/includes/chat-sessions/wpbot-chat-sessions.php
- https://plugins.trac.wordpress.org/browser/chatbot/tags/8.5.0/includes/chat-sessions/wpbot-chat-sessions.php
- https://plugins.trac.wordpress.org/browser/chatbot/tags/8.5.0/includes/chat-sessions/wpbot-chat-sessions.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3608558%40chatbot&new=3608558%40chatbot