Executive brief
The FastBots plugin for WordPress, which is used to integrate AI chatbots into websites, contains a security flaw in its administrative settings. This vulnerability allows an attacker with administrator privileges to inject malicious scripts into the site's configuration. If exploited, these scripts could execute in the browsers of other users, potentially leading to unauthorized actions or data theft, particularly in multi-site WordPress environments.
Technical details
The FastBots plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping within the admin settings component. An authenticated attacker with administrator-level permissions can inject arbitrary web scripts into the plugin's settings page. These scripts are stored in the database and execute whenever a user accesses the affected page. This vulnerability primarily impacts WordPress multi-site installations or environments where the 'unfiltered_html' capability has been disabled for administrators. The issue exists in all versions up to and including 1.0.12.
Affected products
- FastBots FastBots AI Chatbots Up to and including 1.0.12
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory
References
- https://plugins.trac.wordpress.org/browser/fastbots-ai-chatbots/tags/1.0.12/fastbots.php
- https://plugins.trac.wordpress.org/browser/fastbots-ai-chatbots/tags/1.0.12/settings-page.php
- https://plugins.trac.wordpress.org/browser/fastbots-ai-chatbots/trunk/fastbots.php
- https://plugins.trac.wordpress.org/browser/fastbots-ai-chatbots/trunk/settings-page.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/b861e82a-dbff-491d-8a0a-1bfb9a7798ad?source=cve