Skip to content
CVE / MITRECVE Recent··1 min read

CVE-2026-15106 - WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameter

CVE ID :CVE-2026-15106 Published : July 16, 2026, 7:51 a. m. | 1 hour, 7 minutes ago Description :The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.

5. 6. This is due to the plugin not properly verifying that a user is authorized to perform an action.

Originally reported by CVE Recent
0 comments

0 comments

Posting as FierceIbex132
0/1000

No comments yet. Be the first to start the discussion.