SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-15241

HIGH · CVSS 7.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

The AI ChatBot for WooCommerce plugin for WordPress prior to version 4.8.4 is vulnerable due to a lack of authorization and nonce checks on specific AJAX actions. This flaw allows unauthenticated users to exploit the site owner's stored third-party API key, potentially incurring charges to the owner's account and accessing sensitive knowledge-base content. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-15241
Severity
HIGH
CVSS
7.5
EPSS
0.26%
WordPress

Original NVD Description

The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to retrieve indexed knowledge-base content.