CVE-2026-14189 PUBLISHED

WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields

Assigner: WPScan
Reserved: 30.06.2026 Published: 27.07.2026 Updated: 27.07.2026

The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search.

Product Status

Vendor Unknown
Product WPBot
Versions Default: unaffected
  • affected from 0 to 8.5.2 (excl.)

Credits

  • Mustafa Ahmed finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE