WPBot WordPress Plugin Authorization Bypass Vulnerability Allowing Unauthenticated Deletion of Chat Sessions

Vulnerability

A vulnerability exists in the WPBot - AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress, in all versions up to and including 8.5.6. The issue stems from the plugin's failure to properly verify user authorization, allowing unauthenticated attackers to delete arbitrary chat session records from the wpbot_user and wpbot_conversation database tables. This deletion includes chat histories and conversation logs, which can be exploited by supplying a crafted userid value.

Impact

Exploitation of this vulnerability allows for the unauthorized deletion of chat session records and conversation histories from the affected WordPress site.

Reproduction

To reproduce this vulnerability, send a request to the WordPress site with an unverified userid parameter. This can be done through the admin-ajax.php endpoint, which the plugin uses to handle chat session data. The request can be made without authentication, and if the userid parameter is crafted correctly, it will trigger the deletion of the corresponding chat session records from the database.

Remediation

Users are advised to update the WPBot - AI ChatBot for Live Support, Lead Generation, AI Services plugin to version 8.5.7 or later, where this vulnerability has been patched.

Added: Jul 16, 2026, 9:39 AM
Updated: Jul 16, 2026, 9:39 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
8.6
remediation
7.7
relevance
9.7
threat
4.8
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.