WPBot
cpe:2.3:a:quantumcloud:ai_chatbot:*:*:*:*:wordpress:*:*, +1 more
- <= 8.5.6
A vulnerability allowing authorization bypass has been identified in the WPBot - AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress. This issue affects all versions through 8.5.6. The vulnerability arises because the plugin fails to properly verify user authorization for certain actions. As a result, authenticated attackers with subscriber-level access or higher can exploit this flaw to trigger unauthorized re-embedding of stored RAG documents. This exploitation modifies the rag_documents database table and misuses the site owner's paid third-party AI API credits, specifically for OpenAI, Gemini, OpenRouter, or xAI.
Exploitation of this vulnerability allows for unauthorized modification of RAG document embeddings, potentially leading to incorrect data being processed or stored. Additionally, it misappropriates the site owner's AI API credits, which could have financial implications.
To reproduce this vulnerability, an authenticated user with subscriber-level access or higher can upload documents via the WordPress admin interface. The plugin's AJAX handlers for PDF, CSV, and XAML uploads can be used to introduce files that will be processed and embedded using the site's AI API credits. After uploading, the same user can manually sync documents or delete them, further manipulating the rag_documents table and the associated API credit usage.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.