Executive brief
The ChatBot plugin for WordPress, which provides automated customer interaction features, is vulnerable to a security flaw that allows attackers to run malicious scripts in a user's browser. By tricking a site visitor or administrator into clicking a specially crafted link, an attacker could steal login sessions, redirect users to fraudulent websites, or deface page content. This issue affects all versions up to 8.3.2 and can be resolved by updating to version 8.3.3.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in the QuantumCloud ChatBot plugin for WordPress (versions <= 8.3.2) due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by sending a crafted URL to a victim. If the victim, particularly one with elevated privileges, interacts with the link, the attacker's malicious JavaScript will execute within the context of the victim's browser session. This can lead to session hijacking, unauthorized actions on behalf of the user, or delivery of further browser-based exploits. The vulnerability is patched in version 8.3.3.
Affected products
- QuantumCloud ChatBot <= 8.3.2
Timeline
- 2026-05-08: other: Vulnerability reported by researcher HaiND
- 2026-07-01: disclosed: Initial disclosure by Patchstack
- 2026-07-01: patched: Version 8.3.3 released to address the issue
- 2026-07-02: advisory: NVD publication date