CVE-2026-87916

The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every chat visitor by requesting a wide date range.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-12 06:16

Updated : 2026-09-14 21:10


NVD link : CVE-2026-87916

Mitre link : CVE-2026-87916

CVE.ORG link : CVE-2026-87916


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor