Junglewise Threat Intelligence

CVE-2026-57363: QuantumCloud ChatBot stored XSS in WordPress plugin

CVE-2026-57363 · Severity: high · CVSS 7.1 · Published 2026-07-13

Vendors: QuantumCloud.

Executive brief

QuantumCloud ChatBot, a popular WordPress plugin used to add automated chat functionality to websites, is vulnerable to a security flaw that allows attackers to inject malicious scripts. If exploited, an attacker could redirect visitors to fraudulent websites, steal session information, or display unauthorized advertisements. This could lead to a loss of customer trust and potential data theft from users interacting with the affected website.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the QuantumCloud ChatBot plugin for WordPress due to improper neutralization of input during web page generation. The flaw affects versions up to and including 8.3.7. An unauthenticated attacker can inject malicious HTML or JavaScript payloads into the application, which are then stored and executed when a privileged user or guest visits the affected page. Exploitation requires minimal user interaction (such as a user viewing the page where the script is stored). The vulnerability is patched in version 8.3.8.

Affected products

  • QuantumCloud ChatBot <= 8.3.7

Timeline

  • 2026-05-19: disclosed: Reported by researcher daroo
  • 2026-07-06: advisory: Patchstack advisory published
  • 2026-07-13: advisory: NVD published CVE-2026-57363
  • 2026-07-13: patched: Version 8.3.8 released to address the issue

References