Vulnerability  ·  2026-10-07

Kognetiks Chatbot for WordPress — unauthenticated arbitrary file upload (CVSS 10.0)

VulnerabilityHigh impactGlobalCVE-2026-32579
An unauthenticated arbitrary file upload vulnerability (CWE-434) exists in the Kognetiks AI chatbot WordPress plugin through 2.4.9. Patchstack rated it CVSS 10.0; CISA SSVC marks it automatable=yes with total technical impact. An unauthenticated remote attacker can upload arbitrary files to the web root of the site hosting the AI chatbot.
This is one of the most widely installed OpenAI/chatbot integrations for WordPress. A fully unauthenticated arbitrary file upload on the chatbot plugin's host typically converts to remote code execution (upload a web shell under the plugin), giving attackers full control of sites that expose the AI chatbot front-end — a straight path into the site's AI configuration and stored API keys.
Hit the plugin's unauthenticated file-upload endpoint with a malicious filename/payload; the uploaded file lands in a reachable directory and is then executed/requested.
Kognetiks Chatbot for WordPress (chatbot-chatgpt) <= 2.4.9
Patch the plugin to a fixed release (vendor/Patchstack); if not yet released, restrict/disable the plugin and ensure the web root is not writable by the web user.
NVD CVE-2026-32579Patchstack advisoryPatchstack advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →