Junglewise Threat Intelligence

CVE-2026-87916: WPBot AJAX action missing capability and nonce checks

CVE-2026-87916 · Severity: medium · CVSS 5.3 · Published 2026-09-12

Technologies: WPBot.

Executive brief

WPBot is a popular WordPress plugin that provides chat functionality for websites. The plugin's AJAX action for filtering chat sessions lacks authentication and verification checks, allowing unauthenticated visitors to retrieve stored personally identifiable information (names, emails, and phone numbers) from all past chat sessions by sending a simple web request.

Technical details

The vulnerability is a missing authentication and authorization check in the AJAX handler for the qcld_chatbot_session_date_filter action. The action is registered on both authenticated and unauthenticated AJAX hooks without capability checks or nonce verification, and directly echoes visitor records as JSON. An unauthenticated attacker can send a POST request with a wide date range (e.g., 1970-01-01 to 2099-12-31) to wp-admin/admin-ajax.php to retrieve a complete list of stored chat sessions including visitor IDs, session IDs, names, email addresses, and phone numbers. The vulnerability requires at least one chat session to have been captured. The issue is fixed in version 8.6.0.

Affected products

  • WPBot WPBot 8.4.9 to 8.5.9

Timeline

  • 2026-09-10: disclosed
  • 2026-09-12: patched: Fixed in version 8.6.0

References