Beveiligingsadvies

CVE-2026-87916

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-12 06:00:13
Laatst bijgewerkt 2026-09-12 15:28:34
Toegewezen door WPScan
CVSS-score 5.3
Status PUBLISHED

Beschrijving

The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every chat visitor by requesting a wide date range.