Medium severity4.3NVD Advisory· Published Jul 21, 2026· Updated Jul 21, 2026
CVE-2026-14185
CVE-2026-14185
Description
The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-generation settings handlers, allowing authenticated users with subscriber-level access to modify the WPBot WordPress plugin before 8.2.0's configuration.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.