{"api_version":"1","generated_at":"2026-09-12T13:54:30+00:00","cve":"CVE-2026-87916","urls":{"html":"https://cve.report/CVE-2026-87916","api":"https://cve.report/api/cve/CVE-2026-87916.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-87916","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-87916"},"summary":{"title":"WPBot 8.4.9 - 8.5.9 - Unauthenticated Chat Visitor PII Disclosure","description":"The WPBot  WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every chat visitor by requesting a wide date range.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-12 06:16:28","updated_at":"2026-09-12 06:16:28"},"problem_types":["CWE-200 Information Exposure"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/31d65e66-10b1-467a-8b20-ecf4880359e0/","name":"https://wpscan.com/vulnerability/31d65e66-10b1-467a-8b20-ecf4880359e0/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-87916","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87916","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"WPBot","version":"affected 8.4.9 8.6.0 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Seongwon Lee","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"WPBot","vendor":"Unknown","versions":[{"lessThan":"8.6.0","status":"affected","version":"8.4.9","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Seongwon Lee"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The WPBot  WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every chat visitor by requesting a wide date range."}],"problemTypes":[{"descriptions":[{"description":"CWE-200 Information Exposure","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-12T06:00:13.394Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/31d65e66-10b1-467a-8b20-ecf4880359e0/"}],"source":{"discovery":"EXTERNAL"},"title":"WPBot 8.4.9 - 8.5.9 - Unauthenticated Chat Visitor PII Disclosure","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-87916","datePublished":"2026-09-12T06:00:13.394Z","dateReserved":"2026-09-09T15:52:15.226Z","dateUpdated":"2026-09-12T06:00:13.394Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-12 06:16:28","lastModifiedDate":"2026-09-12 06:16:28","problem_types":["CWE-200 Information Exposure"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"87916","Ordinal":"1","Title":"WPBot 8.4.9 - 8.5.9 - Unauthenticated Chat Visitor PII Disclosur","CVE":"CVE-2026-87916","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"87916","Ordinal":"1","NoteData":"The WPBot  WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every chat visitor by requesting a wide date range.","Type":"Description","Title":"WPBot 8.4.9 - 8.5.9 - Unauthenticated Chat Visitor PII Disclosur"}]}}}