Executive brief
WPBot is a WordPress plugin that provides AI-powered chatbot functionality for customer support and lead generation. The plugin is vulnerable to stored cross-site scripting (XSS), allowing unauthenticated attackers to inject malicious scripts that execute in users' browsers when they visit affected pages. This could lead to session hijacking, credential theft, malware distribution, or other malicious activity affecting site visitors.
Technical details
The plugin contains a stored XSS vulnerability in the 'conversation' parameter due to insufficient input sanitization and output escaping. The vulnerability affects all versions up to and including 8.7.3. Although the action is protected by a nonce check, the nonce is localized into every public-facing page via wp_localize_script, rendering it ineffective as an access control barrier for unauthenticated attackers. An attacker can inject arbitrary JavaScript code through the 'conversation' parameter that will be permanently stored and executed in the browsers of all users who subsequently access the affected page.
Affected products
- Toolset WPBot – AI ChatBot for Live Support, Lead Generation, AI Services up to and including 8.7.3
Timeline
- 2026-09-09: disclosed