Unrated severityNVD Advisory· Published Jul 21, 2026· Updated Jul 21, 2026
WPBot AI ChatBot < 8.2.0 - Subscriber+ RAG Settings Update
CVE-2026-14185
Description
The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-generation settings handlers, allowing authenticated users with subscriber-level access to modify the WPBot WordPress plugin before 8.2.0's configuration.
Affected products
1- Range: <8.2.0
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/a6839476-95bf-4785-b128-1e3bc8603ddc/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.