CVE-2026-87918: WPBot < 8.5.7 - Unauthenticated AI Provider API Abuse via Multiple AJAX Actions
The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attackers to make those third-party API calls, and consume the associated cost, using the site's own configured API keys.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WPBotto a version that resolves this vulnerability.Fixed in 8.5.7
Event History
Frequently Asked Questions
Who is exposed to this issue?
Sites using WPBot versions earlier than 8.5.7 with AI providers configured are exposed. The affected AJAX actions can use the site's configured provider API keys.
What does an attacker need to exploit it?
An attacker does not need authentication because the affected AJAX actions lack authorization and nonce checks. They can submit prompts that WPBot relays to configured third-party AI providers.
What is the likely impact of exploitation?
Attackers can cause AI-provider API calls to be made using the site's own configured API keys. This can consume the associated third-party API usage and cost.