CyberRota Analysis
AI-GeneratedThe WPBot WordPress plugin prior to version 8.5.2 is vulnerable to SQL injection due to insufficient validation of administrator-configured field identifiers in SQL queries. This flaw allows users with administrator access to execute arbitrary SQL commands when a visitor initiates a search, potentially compromising the database. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search.