SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-87916

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The WPBot plugin for WordPress versions prior to 8.6.0 is vulnerable to unauthorized access, as it lacks proper capability and nonce checks on its AJAX action for listing stored chat sessions. This flaw enables unauthenticated attackers to extract sensitive information, including names, email addresses, and phone numbers of all chat visitors within a specified date range. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-87916
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%
WordPress

Original NVD Description

The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every chat visitor by requesting a wide date range.