Junglewise Threat Intelligence

CVE-2026-2955: AIWU AI Chatbot & Workflow Automation Stored XSS via X-Forwarded-For

CVE-2026-2955 · Severity: medium · CVSS 6.4 · Published 2026-05-20

Executive brief

The AI Chatbot & Workflow Automation plugin for WordPress is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. This occurs because the plugin does not properly check information sent in web request headers before saving it. If exploited, an attacker could execute unauthorized code in the browsers of site visitors or administrators, though the impact is limited by a small character limit for the injected data.

Technical details

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability due to insufficient input sanitization and output escaping of the 'X-Forwarded-For' HTTP header. An unauthenticated or low-privileged attacker can send a specially crafted header containing malicious JavaScript, which is then stored by the plugin and executed when a user views the affected page. While the vulnerability allows for arbitrary script execution, practical exploitation is significantly constrained by a 20-character storage limit for the injected payload. The issue is present in versions up to 1.4.14 and has been addressed in subsequent updates.

Affected products

  • AIWU AI Chatbot & Workflow Automation by AIWU up to, and including, 1.4.14

Timeline

  • 2026-05-20: disclosed
  • 2026-05-20: advisory

References

Related threats