CVE-2026-16773 MEDIUM

CVE-2026-16773: WPBot <= 8.5.9 - Unauthenticated Sensitive Information Exposure in 'wpbot_send_email_transcript' AJAX Action

Vendor Quantumcloud
Product WPBot – AI ChatBot for Live Support, Lead Generation, AI Services
Weakness CWE-200 · Info exposure
Published July 28, 2026
Last update July 28, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and associated user PII — including names, email addresses, and phone numbers — stored in the wpbot_user and wpbot_conversation tables to an attacker-controlled email address.

Explanation of Vulnerability in Simple Terms

02Summary

WPBot versions up to 8.5.9 expose sensitive information to unauthenticated attackers over the network. The vulnerability allows unauthorized access to data without requiring user interaction or special conditions. Site administrators should update to a version newer than 8.5.9 to prevent information disclosure.

What an attacker can do

03Attacker Capabilities

Read sensitive information from the site without authentication.

Potential impact on your site

04Site Impact

Visitor data, configuration, or other sensitive information may be exposed to anyone on the internet.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

July 28, 2026 CVE published

Related vulnerabilities

08Related CVE