Cross-Site Scripting
17 records38.6%First: 2023. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 44 vulnerability records associated with WPBot – AI ChatBot for Live Support, Lead Generation, AI Services, published between 2023 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2023 | 22 | |
| 2024 | 5 | |
| 2025 | 6 | |
| 2026 | 11 |
| Severity | Records | Share |
|---|---|---|
| Critical | 5 | 11.4% |
| High | 5 | 11.4% |
| Medium | 34 | 77.3% |
First: 2023. Latest: 2026.
First: 2023. Latest: 2026.
First: 2023. Latest: 2026.
First: 2023. Latest: 2023.
First: 2023. Latest: 2025.
First: 2024. Latest: 2024.
First: 2023. Latest: 2023.
First: 2023. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
8.6.08.5.78.3.88.5.28.3.38.5.08.2.07.9.97.8.07.7.47.4.07.1.06.7.56.2.46.3.65.5.85.3.65.1.14.9.74.9.34.9.14.7.94.7.84.5.64.5.54.6.14.4.54.5.14.4.94.4.74.4.84.3.14.2.9Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-8.5.9 | WPBot <= 8.5.9 - Unauthenticated Sensitive Information Exposure in 'wpbot_send_email_transcript' AJAX Action | July 27, 2026 | 8.6.0 | Medium |
*-8.5.9 | WPBot <= 8.5.9 - Missing Authorization to Unauthenticated Email Relay via wpcs_send_email AJAX Action | July 27, 2026 | 8.6.0 | Medium |
*-8.5.6 | WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameter | July 15, 2026 | 8.5.7 | Medium |
*-8.5.6 | WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Function | July 15, 2026 | 8.5.7 | Medium |
*-8.3.7 | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 8.3.7 - Unauthenticated Stored Cross-Site Scripting | July 6, 2026 | 8.3.8 | High |
*-8.5.1 | WPBot AI ChatBot <= 8.5.1 - Authenticated (Administrator+) SQL Injection | July 6, 2026 | 8.5.2 | Medium |
*-8.3.2 | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 8.3.2 - Reflected Cross-Site Scripting | July 1, 2026 | 8.3.3 | Medium |
*-8.4.9 | WPBot <= 8.4.9 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter | June 30, 2026 | 8.5.0 | High |
*-8.1.0 | WPBot AI ChatBot <= 8.1.0 - Missing Authorization | June 30, 2026 | 8.2.0 | Medium |
*-7.9.7 | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 7.9.7 - Missing Authorization | April 23, 2026 | 7.9.9 | Medium |
*-7.7.9 | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 7.7.9 - Unauthenticated SQL Injection | March 20, 2026 | 7.8.0 | High |
*-7.7.3 | ChatBot <= 7.7.3 - Missing Authorization | October 13, 2025 | 7.7.4 | Medium |
*-7.3.9 | ChatBot <= 7.3.9 - Missing Authorization | October 12, 2025 | 7.4.0 | Medium |
*-7.0.0 | AI ChatBot for WordPress <= 7.1.0 - Authenticated (Admin+) Stored Cross-Site Scripting | August 19, 2025 | 7.1.0 | Medium |
*-6.7.3 | ChatBot <= 6.7.3 - Missing Authorization | June 27, 2025 | 6.7.5 | Medium |
*-6.2.3 | AI ChatBot for WordPress – WPBot <= 6.2.3 - Authenticated (Admin+) Stored Cross-Site Scripting | March 3, 2025 | 6.2.4 | Medium |
*-6.3.5 | ChatBot <= 6.3.5 - Authenticated (Contributor+) Local File Inclusion | February 23, 2025 | 6.3.6 | High |
*-5.5.7 | AI ChatBot for WordPress – WPBot <= 5.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting | July 16, 2024 | 5.5.8 | Medium |
*-5.3.4 | AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_delete_callback | May 21, 2024 | 5.3.6 | Medium |
*-5.3.4 | AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_upload_callback | May 21, 2024 | 5.3.6 | Medium |
*-5.3.4 | AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_list_callback | May 21, 2024 | 5.3.6 | Medium |
*-5.1.0 | ChatBot <= 5.1.0 - Unauthenticated PHP Object Injection | January 19, 2024 | 5.1.1 | Critical |
*-4.7.8 | ChatBot <= 4.7.8 - Authenticated (Administrator+) SQL Injection | November 23, 2023 | 4.7.9 | High |
4.8.6-4.9.6 | ChatBot 4.8.6 - 4.9.6 - Authenticated (Administrator+) Stored Cross-Site Scripting in FAQ Builder | November 1, 2023 | 4.9.7 | Medium |
*-4.8.9 | AI ChatBot <= 4.8.9 - Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_user | October 11, 2023 | 4.9.1 | Medium |
Selected source records
Published: July 27, 2026
Published: July 27, 2026
Published: July 15, 2026
Published: July 15, 2026
Published: July 6, 2026
Published: July 6, 2026
Published: July 1, 2026
Published: June 30, 2026
Published: April 12, 2023
Published: October 11, 2023
Published: January 19, 2024
Published: October 11, 2023
Published: October 11, 2023
Published: February 23, 2025
Published: March 20, 2026
Published: June 30, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.