Executive brief
The ChatBot plugin for WordPress, which provides automated customer interaction features, contains a security flaw in its access control mechanisms. An individual with a basic 'Subscriber' account on the website could exploit this to perform actions they are not authorized to do. This could lead to unauthorized changes to the chatbot's configuration or cause service disruptions, potentially impacting customer support operations.
Technical details
A broken access control vulnerability exists in the ChatBot plugin for WordPress due to missing authorization checks (CWE-862) in certain functions. An attacker authenticated with low-level 'Subscriber' privileges can exploit this flaw over the network without any user interaction. The vulnerability allows these users to execute actions typically reserved for higher-privileged accounts, potentially leading to unauthorized data modification or a denial-of-service condition. The issue is addressed in version 7.9.9.
Affected products
- QuantumCloud ChatBot <= 7.9.7
Timeline
- 2026-03-20: other: Reported by researcher Mehdi Ouassou
- 2026-04-23: advisory: Initial advisory published by Patchstack
- 2026-06-15: disclosed: CVE published to NVD
- 2026-04-23: patched: Patch released in version 7.9.9