Skip to content
CVE / MITRECVE Recent··1 min read

CVE-2026-15610 - WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Function

CVE ID :CVE-2026-15610 Published : July 16, 2026, 7:51 a. m. | 1 hour, 7 minutes ago Description :The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.

5. 6. This is due to the plugin not properly verifying that a user is authorized to perform an action.

Originally reported by CVE Recent
0 comments

0 comments

Posting as BoldOtter423
0/1000

No comments yet. Be the first to start the discussion.