Vulnerability  ·  2026-10-01

Conversational Forms for ChatBot PHP object injection (WordPress AI chatbot plugin)

VulnerabilityMedium impactGlobalCVE-2026-95531
NVD published 2026-09-30 with CVSS 8.8; Patchstack advisory documents the injection class in the chatbot-adjacent forms plugin.
Chatbot plugins are the entry point to WordPress AI deployments; object injection at subscriber level broadens the AI-plugin attack surface.
Subscriber-privilege PHP object injection reachable through the plugin's form handling path, potentially chaining to arbitrary property manipulation or code execution depending on available gadgets.
WordPress Conversational Forms for ChatBot plugin <= 1.5.0
Update the Conversational Forms for ChatBot plugin beyond 1.5.0.
Patchstack advisoryNVD
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →