CVE-2025-26932: WordPress WPBot plugin <= 6.3.5 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in QuantumCloud ChatBot chatbot allows PHP Local File Inclusion.This issue affects ChatBot: from n/a through <= 6.3.5.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26932?
CVE-2025-26932 is categorized as a critical vulnerability due to its potential for remote file inclusion which may lead to full compromise of the affected system.
How do I fix CVE-2025-26932?
To fix CVE-2025-26932, upgrade QuantumCloud ChatBot and WordPress WPBot plugin to versions that are above 6.3.5 to eliminate the local file inclusion vulnerability.
What systems are affected by CVE-2025-26932?
CVE-2025-26932 affects QuantumCloud ChatBot versions n/a through 6.3.5 and the WordPress WPBot plugin up to and including version 6.3.5.
What could happen if CVE-2025-26932 is exploited?
Exploitation of CVE-2025-26932 could allow attackers to include malicious files on the server, potentially leading to full system control.
Is CVE-2025-26932 publicly known?
Yes, CVE-2025-26932 is a publicly disclosed vulnerability, making it critical for users to apply patches immediately.