Junglewise Threat Intelligence

CVE-2026-15241: WoowBot Chatbot missing authorization check on AJAX action

CVE-2026-15241 · Severity: high · CVSS 7.5 · Published 2026-08-02

Executive brief

WoowBot is a WordPress plugin that integrates AI chatbots with WooCommerce stores, including support for Google Gemini API. The plugin fails to verify user authentication on an AJAX endpoint, allowing any visitor to submit requests that are signed with the site owner's stored API credentials. This exposes the owner to financial harm as unauthorized API calls are billed to their account, and can leak sensitive knowledge-base content if enabled.

Technical details

The vulnerability is a missing authorization and nonce check (CWE-284: Improper Access Control) on the qcld_gemini_response AJAX action. An unauthenticated attacker can directly POST to wp-admin/admin-ajax.php with action=qcld_gemini_response and arbitrary keywords, which the plugin processes using the site owner's stored Google Gemini API key without validation. The attacker receives the API response directly, effectively using the plugin as an open proxy for the Gemini service. If the optional Retrieval-Augmented Generation (RAG) feature is enabled, submitted keywords are matched against the owner's private knowledge base, potentially leaking indexed content. The attack requires no authentication, nonce, or cookies; a simple unauthenticated POST request suffices. A fix was released in version 4.8.4.

Affected products

  • WoowBot ChatBot for WooCommerce before 4.8.4

Timeline

  • 2026-07-20: disclosed
  • 2026-08-02: patched: Fixed in version 4.8.4

References