CVE-2026-87959: WPBot 8.7.2 - 8.7.5 - Subscriber+ Claude AI Settings Update
The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI provider settings, allowing users with subscriber-level access to overwrite those settings, including the API key used for the WPBot WordPress plugin before 8.7.6's outgoing AI requests.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WPBot pluginto a version that resolves this vulnerability.Fixed in 8.7.6 - Operational
After upgrading to WPBot 8.7.6, rotate the Claude AI provider API key used by the WPBot WordPress plugin, since subscriber-level users could overwrite it in versions before 8.7.6.
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user with subscriber-level access can invoke the affected AJAX action. The issue does not require administrator privileges.
What settings can an attacker change?
An attacker can overwrite the Claude AI provider settings, including the API key used for WPBot's outgoing AI requests.
Which installations are affected?
WPBot versions before 8.7.6 are affected. The reported vulnerable range includes versions 8.7.2 through 8.7.5.