The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search.
Metrics
Affected Vendors & Products
References
History
Mon, 27 Jul 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search. | |
| Title | WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-27T06:00:04.296Z
Reserved: 2026-06-30T08:25:44.832Z
Link: CVE-2026-14189
No data.
No data.
No data.
OpenCVE Enrichment
No data.