WordPress Plugin Vulnerabilities

WPBot 8.4.9 - 8.5.9 - Unauthenticated Chat Visitor PII Disclosure

Description

The plugin does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every chat visitor by requesting a wide date range.

Proof of Concept

Affects Plugins

Fixed in 8.6.0

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Seongwon Lee
Submitter
Seongwon Lee
Verified
Yes

Timeline

Publicly Published
2026-09-10 (about 2 days ago)
Added
2026-09-10 (about 1 day ago)
Last Updated
2026-09-10 (about 1 day ago)

Other