CVE-2025-9111: WPBOT < 7.1.0 - Admin+ Stored XSS
The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9111?
CVE-2025-9111 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2025-9111?
To fix CVE-2025-9111, update the AI ChatBot plugin to version 7.1.0 or later.
Who is affected by CVE-2025-9111?
CVE-2025-9111 affects high privilege users, such as admin roles, who utilize the vulnerable AI ChatBot plugin for WordPress.
What are the consequences of exploiting CVE-2025-9111?
Exploiting CVE-2025-9111 can lead to stored cross-site scripting attacks, allowing attackers to execute malicious scripts in users' browsers.
Is there a patch available for CVE-2025-9111?
Yes, a patch is included in the release of AI ChatBot version 7.1.0 that addresses the vulnerability.