What the vulnerability does
01Description
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and associated user PII — including names, email addresses, and phone numbers — stored in the wpbot_user and wpbot_conversation tables to an attacker-controlled email address.
Explanation of Vulnerability in Simple Terms
02Summary
WPBot versions up to 8.5.9 expose sensitive information to unauthenticated attackers over the network. The vulnerability allows unauthorized access to data without requiring user interaction or special conditions. Site administrators should update to a version newer than 8.5.9 to prevent information disclosure.
What an attacker can do
03Attacker Capabilities
Read sensitive information from the site without authentication.
Potential impact on your site
04Site Impact
Visitor data, configuration, or other sensitive information may be exposed to anyone on the internet.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
July 28, 2026
CVE published