Unrated severityNVD Advisory· Published Aug 2, 2026· Updated Aug 3, 2026
ChatBot for eCommerce – WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_gemini_response
CVE-2026-15241
Description
The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to retrieve indexed knowledge-base content.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <4.8.4
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/81ab9ecd-5d7b-4d10-b255-65af869c46e2/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.