Unrated severityNVD Advisory· Published Sep 16, 2026
CVE-2026-87959
CVE-2026-87959
Description
The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI provider settings, allowing users with subscriber-level access to overwrite those settings, including the API key used for the WPBot WordPress plugin before 8.7.6's outgoing AI requests.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.