Plugin Vulnerability Hub
Plugin 34 known issues Latest disclosed Mar 20, 2026

WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Vulnerabilities

Review known vulnerability records for the WordPress plugin WPBot – AI ChatBot for Live Support, Lead Generation, AI Services (`chatbot`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-32499, CVE-2025-62952 and CVE-2025-64277, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
34
High or Critical
8
Patch Coverage
100%
Last Updated
Mar 26, 2026
Priority CVE Quick Links

Fast paths into WPBot – AI ChatBot for Live Support, Lead Generation, AI Services CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
33
CVE-2024-22309 Critical 5.1.1
CVE-2024-22309 WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Vulnerability

ChatBot <= 5.1.0 - Unauthenticated PHP Object Injection

CVE-2023-5204 Critical 4.9.1
CVE-2023-5204 WPBot – AI ChatBot for Live Support, Lead Generation, AI Services SQL Injection

AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_response

CVE-2023-1650 Critical 4.4.7
CVE-2023-1650 WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Vulnerability

ChatBot <= 4.4.6 - Unauthenticated PHP Object Injection via Cookies

CVE-2023-5241 Critical 4.9.1
CVE-2023-5241 WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Vulnerability

AI ChatBot <= 4.8.9 and 4.9.2 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_file

CVE-2023-5212 Critical 4.9.1
CVE-2023-5212 WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Vulnerability

AI ChatBot <= 4.8.9 and 4.9.2- Authenticated (Subscriber+) Arbitrary File Deletion via qcld_openai_delete_training_file

CVE-2025-26932 High 6.3.6
CVE-2025-26932 WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Local File Inclusion

ChatBot <= 6.3.5 - Authenticated (Contributor+) Local File Inclusion

CVE-2026-32499 High 7.8.0
CVE-2026-32499 WPBot – AI ChatBot for Live Support, Lead Generation, AI Services SQL Injection

WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 7.7.9 - Unauthenticated SQL Injection

CVE-2023-48741 High 4.7.9
CVE-2023-48741 WPBot – AI ChatBot for Live Support, Lead Generation, AI Services SQL Injection

ChatBot <= 4.7.8 - Authenticated (Administrator+) SQL Injection

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for WPBot – AI ChatBot for Live Support, Lead Generation, AI Services so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
34 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
5 critical and 3 high severity findings.
Recent CVEs
CVE-2026-32499, CVE-2025-62952 and CVE-2025-64277
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for WPBot – AI ChatBot for Live Support, Lead Generation, AI Services

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2026-32499
CVE-2026-32499: WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 7.7.9 - Unauthenticated SQL Injection

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL que...

Published
Mar 20, 2026
Patched Release
7.8.0
Affected Versions
Versions up to 7.7.9
Next Step
Update to 7.8.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-62952
CVE-2025-62952: ChatBot <= 7.7.3 - Missing Authorization

The ChatBot plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.7.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized ac...

Published
Oct 13, 2025
Patched Release
7.7.4
Affected Versions
Versions up to 7.7.3
Next Step
Update to 7.7.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-64277
CVE-2025-64277: ChatBot <= 7.3.9 - Missing Authorization

The AI ChatBot – WPBot for Live Support and Lead Generation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.3.9. This makes it possible for unauthenticated attackers to perform an un...

Published
Oct 12, 2025
Patched Release
7.4.0
Affected Versions
Versions up to 7.3.9
Next Step
Update to 7.4.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-9111
CVE-2025-9111: AI ChatBot for WordPress <= 7.1.0 - Authenticated (Admin+) Stored Cross-Site Scripting

The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

Published
Aug 19, 2025
Patched Release
7.1.0
Affected Versions
Versions up to 7.0.0
Next Step
Update to 7.1.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-53200
CVE-2025-53200: ChatBot <= 6.7.3 - Missing Authorization

The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.7.3. This makes it possible for authenticated attackers, with Subscriber-level access and above,...

Published
Jun 27, 2025
Patched Release
6.7.5
Affected Versions
Versions up to 6.7.3
Next Step
Update to 6.7.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-0329
CVE-2025-0329: AI ChatBot for WordPress – WPBot <= 6.2.3 - Authenticated (Admin+) Stored Cross-Site Scripting

The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

Published
Mar 03, 2025
Patched Release
6.2.4
Affected Versions
Versions up to 6.2.3
Next Step
Update to 6.2.4 or newer if supported.
Plugin High Patched: Yes CVE-2025-26932
CVE-2025-26932: ChatBot <= 6.3.5 - Authenticated (Contributor+) Local File Inclusion

The ChatBot plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.3.5. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the executio...

Published
Feb 23, 2025
Patched Release
6.3.6
Affected Versions
Versions up to 6.3.5
Next Step
Update to 6.3.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-6669
CVE-2024-6669: AI ChatBot for WordPress – WPBot <= 5.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting

The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

Published
Jul 16, 2024
Patched Release
5.5.8
Affected Versions
Versions up to 5.5.7
Next Step
Update to 5.5.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-0453
CVE-2024-0453: AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_delete_callback

The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-le...

Published
May 21, 2024
Patched Release
5.3.6
Affected Versions
Versions up to 5.3.4
Next Step
Update to 5.3.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-0452
CVE-2024-0452: AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_upload_callback

The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_upload_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-le...

Published
May 21, 2024
Patched Release
5.3.6
Affected Versions
Versions up to 5.3.4
Next Step
Update to 5.3.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-0451
CVE-2024-0451: AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_list_callback

The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the openai_file_list_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level acce...

Published
May 21, 2024
Patched Release
5.3.6
Affected Versions
Versions up to 5.3.4
Next Step
Update to 5.3.6 or newer if supported.
Plugin Critical Patched: Yes CVE-2024-22309
CVE-2024-22309: ChatBot <= 5.1.0 - Unauthenticated PHP Object Injection

The ChatBot with AI plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1.0 via deserialization of untrusted input via the last_five_prompt cookies. This makes it possible for unauthenticated attackers to inject a PHP Object. No POP...

Published
Jan 19, 2024
Patched Release
5.1.1
Affected Versions
Versions up to 5.1.0
Next Step
Update to 5.1.1 or newer if supported.