VYPR

WPBot AI ChatBot

by WordPress

CVEs (2)

  • CVE-2026-14189Jul 27, 2026
    risk 0.00cvss epss 0.00

    The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search.

  • CVE-2026-14185Jul 21, 2026
    risk 0.00cvss epss 0.00

    The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-generation settings handlers, allowing authenticated users with subscriber-level access to modify the WPBot WordPress plugin before 8.2.0's configuration.