Junglewise Threat Intelligence

CVE-2026-57710: quantumcloud WoowBot Pro Max arbitrary file upload

CVE-2026-57710 · Severity: critical · CVSS 9.9 · Published 2026-07-13

Vendors: QuantumCloud.

Executive brief

WoowBot Pro Max, a premium WordPress chatbot plugin, contains a critical security flaw that allows users with low-level accounts to upload dangerous files to the server. An attacker could use this to install a 'backdoor,' granting them full control over the website, the ability to steal customer data, or the power to shut down the service entirely. This vulnerability is considered highly dangerous as it can be used in automated mass-exploitation campaigns.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in the quantumcloud WoowBot Pro Max plugin for WordPress. The flaw allows an authenticated attacker, typically with 'Subscriber' or higher privileges, to upload files with dangerous extensions (such as .php) to the web server. Because the plugin fails to properly validate file types or restrict upload locations, an attacker can achieve remote code execution (RCE) by accessing the uploaded malicious file. This can lead to a complete compromise of the WordPress environment. The issue is resolved in version 14.1.8.

Affected products

  • quantumcloud WoowBot Pro Max <= 14.1.7

Timeline

  • 2026-06-22: other: Reported by researcher Jamaal Ahmed
  • 2026-07-09: advisory: Initial advisory published by Patchstack
  • 2026-07-13: disclosed: CVE published to NVD
  • 2026-07-13: patched: Version 14.1.8 released to address the vulnerability

References