{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wpbot--ai-chatbot-for-live-support-lead-generation-ai-services--8.7.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wpbot_project:wpbot:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-83593"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WPBot – AI ChatBot for Live Support, Lead Generation, AI Services (\u003c= 8.7.3)"],"_cs_severities":["high"],"_cs_tags":["xss","web-application-vulnerability","wordpress","cve-2026-83593"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe WPBot - AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is affected by a Stored Cross-Site Scripting (XSS) vulnerability identified as CVE-2026-83593. The vulnerability exists in the 'conversation' parameter and affects all versions up to and including 8.7.3. It stems from insufficient input sanitization and output escaping.\u003c/p\u003e\n\u003cp\u003eDefenders should note that the plugin's nonce check, intended to act as an access control mechanism, is rendered ineffective because it is localized into public-facing pages via the 'wp_localize_script' function. This allows unauthenticated attackers to bypass the check and inject malicious payloads into the conversation flow. Once stored, these scripts execute within the browser context of any user, including administrators, who views the compromised page. This vulnerability poses a significant risk to WordPress sites utilizing this plugin for customer support, as it can lead to session hijacking, unauthorized actions, or credential theft.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to execute arbitrary JavaScript in the victim's browser session. If an administrator views the compromised page, the attacker could potentially take full control of the WordPress site. The plugin is widely used for lead generation and customer support, making this a high-impact vector for sites relying on interactive chatbot functionality.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the WPBot plugin to the latest available version (beyond 8.7.3) as soon as the vendor releases a patch.\u003c/li\u003e\n\u003cli\u003eIn the absence of a patch, disable the WPBot plugin on public-facing sites.\u003c/li\u003e\n\u003cli\u003eReview access logs for POST requests containing JavaScript-like patterns in the 'conversation' parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T06:48:28Z","date_published":"2026-09-09T06:48:28Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wpbot-xss/","summary":"The WPBot - AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability in versions up to 8.7.3, allowing unauthenticated attackers to execute arbitrary web scripts.","title":"Stored Cross-Site Scripting in WPBot WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-wpbot-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - WPBot – AI ChatBot for Live Support, Lead Generation, AI Services (\u003c= 8.7.3)","version":"https://jsonfeed.org/version/1.1"}