Junglewise Threat Intelligence

CVE-2026-16773: QuantumCloud WPBot sensitive information exposure in chat transcripts

CVE-2026-16773 · Severity: medium · CVSS 5.3 · Published 2026-07-28

Technologies: QuantumCloud WPBot – AI ChatBot for Live Support, Lead Generation, AI Services. Vendors: QuantumCloud.

Executive brief

A vulnerability in the WPBot plugin for WordPress, which provides AI-driven customer support and lead generation, allows unauthorized individuals to access private chat logs. An attacker can remotely trigger the plugin to send full conversation transcripts and user contact details, such as names and phone numbers, to an email address they control. This could lead to the exposure of sensitive customer data and proprietary business interactions.

Technical details

The WPBot plugin for WordPress is vulnerable to sensitive information exposure due to an insecure implementation of the 'wpbot_send_email_transcript_free' function. This function lacks proper authorization or validation, allowing unauthenticated remote attackers to exfiltrate data from the 'wpbot_user' and 'wpbot_conversation' database tables. By sending a crafted request, an attacker can direct the plugin to email full chat transcripts and associated Personally Identifiable Information (PII), including names, email addresses, and phone numbers, to an arbitrary email address. The issue is present in all versions up to 8.5.9 and has been addressed in subsequent updates.

Affected products

  • QuantumCloud WPBot – AI ChatBot for Live Support, Lead Generation, AI Services up to, and including, 8.5.9

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory

References

Related threats