Security Advisory

CVE-2026-14185

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-21 06:00:02
Last updated 2026-07-21 13:32:05
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-generation settings handlers, allowing authenticated users with subscriber-level access to modify the WPBot WordPress plugin before 8.2.0's configuration.