CVE-2025-60223: WordPress WPBot Pro Wordpress Chatbot plugin <= 13.6.5 - Arbitrary File Deletion vulnerability
Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <= 13.6.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
WPBot Pro Wordpress Chatbot pluginfrom your environment.Uninstall the WPBot Pro Wordpress Chatbot plugin if it is not required.
- Configuration
Remove or revoke any file-deletion or file-management capabilities from the Subscriber role so subscribers cannot delete files (mitigate vulnerability in WPBot Pro <= 13.6.5).
WordPress user roles/capabilities file deletion capability for Subscriber role = remove or restrict - Compensating control
Disable/deactivate the WPBot Pro plugin or restrict access to its functionality (and restrict plugin management to trusted administrator accounts) until a vendor-published patch is available. Note: versions <= 13.6.5 are reported vulnerable.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60223?
CVE-2025-60223 has a severity rating of high at 7.7.
How do I fix CVE-2025-60223?
To fix CVE-2025-60223, update the WPBot Pro WordPress Chatbot plugin to version 13.6.6 or later.
What type of vulnerability is CVE-2025-60223?
CVE-2025-60223 is an Arbitrary File Deletion vulnerability due to path traversal in the WPBot Pro plugin.
Who is affected by CVE-2025-60223?
Subscribers of sites using WPBot Pro WordPress Chatbot versions 13.6.5 and earlier are affected by CVE-2025-60223.
When was CVE-2025-60223 published?
CVE-2025-60223 was published on June 17, 2026.