Junglewise Threat Intelligence

CVE-2026-2993: AIWU AI Chatbot & Workflow Automation SQL injection in getListForTbl

CVE-2026-2993 · Severity: high · CVSS 7.5 · Published 2026-05-12

Executive brief

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to a security flaw that allows unauthorized access to the website's database. This plugin is used to integrate AI-driven chat and automation features into WordPress sites. An attacker could exploit this vulnerability to steal sensitive information, such as user credentials or customer data, potentially leading to a full site compromise or data breach.

Technical details

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress contains a SQL injection vulnerability within the getListForTbl() function. The root cause is the failure to properly escape user-supplied parameters and a lack of SQL query preparation. This allows unauthenticated remote attackers to append malicious SQL commands to existing queries. Successful exploitation enables the extraction of sensitive data from the WordPress database. While version 1.4.11 introduced a partial mitigation via a nonce check restricted to administrators, the vulnerability is reported to persist in versions up to 1.4.17.

Affected products

  • AIWU AI Chatbot & Workflow Automation by AIWU up to, and including, 1.4.17

Timeline

  • 2026-05-12: advisory: CVE-2026-2993 published by NVD

References

Related threats