Vulnerability  ·  2026-06-16

ChatBot WordPress Plugin — Subscriber Broken Access Control (CVSS 7.1)

VulnerabilityMedium impactGlobalCVE-2026-40788
The ChatBot plugin for WordPress, a widely-deployed AI chatbot solution, contains a broken access control vulnerability in versions up to and including 7.9.7. Published June 15, 2026 (CVSS 7.1 HIGH). Subscriber-level authenticated users can access functionality or data that should be restricted to higher roles such as Administrator.
Chatbot plugins frequently store conversation histories containing sensitive customer data, AI model API credentials, and custom prompt/system instruction configurations that define the chatbot's behavior. A subscriber-level access control bypass allows low-trust registered users to read private chat logs, exfiltrate AI API keys, or modify the bot's system prompts to hijack its behavior for all subsequent users.
An authenticated attacker with Subscriber-level privileges exploits broken access control logic in the ChatBot plugin ≤ 7.9.7 to access or modify chatbot configuration, conversation logs, or other functionality restricted to higher-privileged roles.
ChatBot for WordPress ≤ 7.9.7
Update ChatBot to version 7.9.8 or later. Advisory: https://patchstack.com/database/wordpress/plugin/chatbot/vulnerability/wordpress-chatbot-plugin-7-9-7-broken-access-control-vulnerability
Sources
Patchstack Advisory — ChatBot Broken Access Control CVE-2026-40788NVD CVE-2026-40788
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →