Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 28 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Quantumcloud
Quantumcloud wpbot – Ai Chatbot For Live Support, Lead Generation, Ai Services Wordpress Wordpress wordpress |
|
| Vendors & Products |
Quantumcloud
Quantumcloud wpbot – Ai Chatbot For Live Support, Lead Generation, Ai Services Wordpress Wordpress wordpress |
Tue, 28 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handler. This is due to the wpcs_send_email() function being registered on both wp_ajax_wpcs_send_email and wp_ajax_nopriv_wpcs_send_email with no nonce verification, capability check, or rate limiting, while forwarding attacker-controlled recipient, subject, and body directly to wp_mail(). This makes it possible for unauthenticated attackers to send arbitrary emails to any recipient from the site's domain, enabling spam, phishing, and abuse that can lead to the site's IP/domain being blacklisted. | |
| Title | WPBot <= 8.5.9 - Missing Authorization to Unauthenticated Email Relay via wpcs_send_email AJAX Action | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-07-28T14:53:38.807Z
Reserved: 2026-07-23T17:09:30.160Z
Link: CVE-2026-16774
Updated: 2026-07-28T13:36:32.258Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-28T18:15:03Z