MEDIUM

CVE-2026-87918

2026-09-12 CVSS v3.1
CVSS
5.3

Description

The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attackers to make those third-party API calls, and consume the associated cost, using the site's own configured API keys.

Weakness (CWE)

CWE-284 Improper Access Control

EPSS Score

0.19%
Probability of exploitation in next 30 days
9.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE