Vulnerability  ·  2026-08-03

AI ChatBot for WooCommerce — Unauthenticated AJAX Action Enables API Key Abuse and Billing Fraud

VulnerabilityMedium impactGlobalCVE-2026-15241
Published August 2, 2026 (unrated CVSS in NVD feed; assessed Medium). Missing authorization/nonce validation on one AJAX endpoint allows anonymous abuse of the site's connected LLM API key.
While blast radius is limited to a single niche WooCommerce plugin, unauthenticated abuse of a store owner's paid LLM API key enables both direct financial harm (API billing fraud) and potential disclosure of indexed knowledge-base content — a low-effort, high-frequency abuse pattern typical of AI-chatbot plugins with poor authorization hygiene.
An AJAX action lacks authorization and nonce checks, letting unauthenticated visitors trigger requests that use the site owner's stored third-party AI API key (e.g., OpenAI), incurring billing costs to the owner's account and, if an optional knowledge-base feature is enabled, potentially accessing indexed KB content.
AI ChatBot for WooCommerce WordPress plugin < 4.8.4
Update AI ChatBot for WooCommerce to version 4.8.4 or later.
NVD - CVE-2026-15241BaseFortify CVE Report - CVE-2026-15241
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →