CVE-2026-87916
Deferred
Deferred - Pending Action
Unauthenticated Chat Session Data Exposure in WPBot WordPress Plugin
Vulnerability report for CVE-2026-87916, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-12
Last updated on: 2026-09-14
Assigner: WPScan
Description
Description
The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every chat visitor by requesting a wide date range.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wpbot | wpbot | From 8.4.9 (inc) to 8.5.9 (inc) |
| wpbot | wpbot | to 8.6.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |