MEDIUM
CVE-2026-87918
CVSS
5.3
Description
The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attackers to make those third-party API calls, and consume the associated cost, using the site's own configured API keys.
Weakness (CWE)
CWE-284
Improper Access Control
EPSS Score
0.19%
Probability of exploitation in next 30 days
9.3th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.