CVE-2026-16773
Received Received - Intake

Sensitive Information Exposure in WPBot WordPress Plugin

Vulnerability report for CVE-2026-16773, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: Wordfence

Description

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and associated user PII β€” including names, email addresses, and phone numbers β€” stored in the wpbot_user and wpbot_conversation tables to an attacker-controlled email address.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-28
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpbot ai_chatbot_for_live_support to 8.5.9 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WPBot plugin for WordPress has a vulnerability that allows unauthenticated attackers to access sensitive chat transcripts and user data. The flaw exists in versions up to 8.5.9 and is triggered through the wpbot_send_email_transcript_free function. Attackers can send a crafted request to exfiltrate full chat logs containing personally identifiable information (PII) such as names, email addresses, and phone numbers stored in the plugin's database tables.

Detection Guidance

Check WordPress plugin logs for unusual email transcript requests or unauthorized access to wpbot_user and wpbot_conversation tables. Monitor network traffic for outgoing connections to unknown email addresses.

Impact Analysis

If you use the WPBot plugin, attackers could steal sensitive user data from chat transcripts without needing authentication. This could lead to privacy breaches, identity theft, or targeted phishing attacks against your users. The exposed data includes contact details and conversation history, which may contain confidential information.

Compliance Impact

This vulnerability likely violates GDPR and other privacy regulations due to unauthorized access to personal data. GDPR requires protecting user PII, and HIPAA mandates safeguarding protected health information. The exposure of chat transcripts with names, emails, and phone numbers could result in regulatory fines and legal consequences for non-compliance.

Mitigation Strategies

Update the WPBot plugin to the latest version beyond 8.5.9. If an update is unavailable, disable the plugin immediately. Review database tables for unauthorized access and restrict database permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16773. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart