CVE-2026-87959
N/A
N/A
Summary
The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI provider settings, allowing users with subscriber-level access to overwrite those settings, including the API key used for the WPBot WordPress plugin before 8.7.6's outgoing AI requests.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | WPBot | 8.7.2 < 8.7.6 | affected |
Weaknesses
- CWE-284 Improper Access Control
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.