
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Security & Risk Analysis
wordpress.org/plugins/chatbotAI ChatBot for WordPress WPBot - Automated 24/7 Live Chat Customer Support. NATIVE, Lead Generation, Forms, Gemini, DialogFlow, ChatGPT, OpenRouter
Is WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Safe to Use in 2026?
Mostly Safe
Score 76/100WPBot – AI ChatBot for Live Support, Lead Generation, AI Services is generally safe to use. 35 past CVEs were resolved.
The "chatbot" plugin v7.8.9 presents a concerning security posture, despite some positive code hygiene indicators. While a significant portion of SQL queries utilize prepared statements and a majority of output is properly escaped, the plugin suffers from a large attack surface with a substantial number of unprotected AJAX handlers. The presence of "unserialize" as a dangerous function, coupled with five high-severity taint flows, suggests potential for critical vulnerabilities. The plugin's history of 33 known CVEs, including five critical and two high-severity ones, with common patterns like missing authorization, path traversal, and SQL injection, is a strong indicator of recurrent security weaknesses. The fact that the last vulnerability was reported in October 2025, even though it's currently unpatched, is also a red flag. Overall, the plugin exhibits a history of severe security flaws and possesses characteristics that make it a high-risk component.
Key Concerns
- Large attack surface without auth checks
- Dangerous function: unserialize
- High severity taint flows
- Total known CVEs (33)
- Critical CVEs (5)
- High CVEs (2)
- Vulnerability type: Missing Authorization
- Vulnerability type: Path Traversal
- Vulnerability type: SQL Injection
- Vulnerability type: Deserialization of Untrusted Data
- Unpatched critical CVE
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Security Vulnerabilities
CVEs by Year
Severity Breakdown
35 total CVEs
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 7.9.7 - Missing Authorization
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services <= 7.7.9 - Unauthenticated SQL Injection
ChatBot <= 7.7.3 - Missing Authorization
ChatBot <= 7.3.9 - Missing Authorization
AI ChatBot for WordPress <= 7.1.0 - Authenticated (Admin+) Stored Cross-Site Scripting
ChatBot <= 6.7.3 - Missing Authorization
AI ChatBot for WordPress – WPBot <= 6.2.3 - Authenticated (Admin+) Stored Cross-Site Scripting
ChatBot <= 6.3.5 - Authenticated (Contributor+) Local File Inclusion
AI ChatBot for WordPress – WPBot <= 5.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_list_callback
AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_upload_callback
AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_delete_callback
ChatBot <= 5.1.0 - Unauthenticated PHP Object Injection
ChatBot <= 4.7.8 - Authenticated (Administrator+) SQL Injection
ChatBot 4.8.6 - 4.9.6 - Authenticated (Administrator+) Stored Cross-Site Scripting in FAQ Builder
AI ChatBot <= 4.8.9 and 4.9.2 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_file
AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_response
AI ChatBot <= 4.8.9 and 4.9.2- Authenticated (Subscriber+) Arbitrary File Deletion via qcld_openai_delete_training_file
AI ChatBot <= 4.8.9 and 4.9.2 - Cross-Site Request Forgery on AJAX actions
AI ChatBot <= 4.8.9 and 4.9.2 - Missing Authorization on AJAX actions
AI ChatBot <= 4.8.9 - Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_user
ChatBot <= 4.7.8 - Cross-Site Request Forgery via qc_wp_latest_update_check
ChatBot 4.7.7 - Authenticated (Administrator+) Stored Cross-Site Scripting in Language Settings
ChatBot <= 4.7.7 - Authenticated (Administrator+) Stored Cross-Site Scripting in FAQ Builder
AI ChatBot <= 4.5.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
AI ChatBot <= 4.6.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
AI ChatBot <= 4.5.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
ChatBot <= 4.4.4 - Unauthenticated Stored Cross-Site Scripting via Cross-Site Request Forgery
ChatBot <= 4.4.6 - Unauthenticated PHP Object Injection via Cookies
ChatBot <= 4.4.8 - Unauthenticated Stored Cross-Site Scripting in Admin Dashboard
AI ChatBot <= 4.4.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
ChatBot <= 4.4.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via openai_settings_option_callback
AI ChatBot <= 4.4.7 - Missing Authorization on openai_settings_option_callback
ChatBot <= 4.2.8 - Cross-Site Request Forgery to Stored Cross-Site Scripting and Settings Reset
ChatBot <= 4.3.0 - Authenticated (Admin+) Cross-Site Scripting
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Release Timeline
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Attack Surface
AJAX Handlers 123
Shortcodes 2
WordPress Hooks 70
Maintenance & Trust
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Maintenance & Trust
Maintenance Signals
Community Trust
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Alternatives
AI ChatBot for WordPress by AI BotKit – Live in 2 Minutes, No Code
ai-botkit-for-lead-generation
Add a smart ChatGPT-powered AI chatbot to your WordPress site to automate support, answer FAQs, engage visitors 24/7, and escalate when needed.
AI Chatbot – Jotform
jotform-ai-chatbot
AI chatbot that automates support, answers FAQs, drives WooCommerce sales, generates leads, and boosts engagement — easy setup, no coding!
BotPenguin – Generative AI Chatbot with Live Chat & ChatGPT
botpenguinbot
WordPress AI Chatbot with Live Chat & ChatGPT for your website. It automates Customer Support, Lead Generation, Bookings, Marketing, eCommerce, etc.
Social Intents – Live Chat
live-chat-support-by-social-intents
AI Chatbot & Live Chat plugin for WordPress. Chat with visitors using ChatGPT, Claude, Gemini, Slack, Teams, and Google Chat.
AI Chatbot & Live Chat with ChatGPT Support by WebChatAgent
webchatagent
Add an AI chatbot and live chat to your WordPress site. Answer visitors 24/7, capture leads, book appointments and hand over chats to humans when it m …
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Developer Profile
29 plugins · 26K total installs
How We Detect WPBot – AI ChatBot for Live Support, Lead Generation, AI Services
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/chatbot/css/wpbot-style.css/wp-content/plugins/chatbot/css/wpbot-responsive.css/wp-content/plugins/chatbot/css/admin-style.css/wp-content/plugins/chatbot/js/wpbot-frontend.js/wp-content/plugins/chatbot/js/wpbot-admin.js/wp-content/plugins/chatbot/js/wpbot-script.js/wp-content/plugins/chatbot/includes/tinymce/tinymce.min.jswp-content/plugins/chatbot/js/wpbot-frontend.jswp-content/plugins/chatbot/js/wpbot-admin.jswp-content/plugins/chatbot/js/wpbot-script.jswp-content/plugins/chatbot/includes/tinymce/tinymce.min.jschatbot/css/wpbot-style.css?ver=chatbot/css/wpbot-responsive.css?ver=chatbot/css/admin-style.css?ver=chatbot/js/wpbot-frontend.js?ver=chatbot/js/wpbot-admin.js?ver=chatbot/js/wpbot-script.js?ver=HTML / DOM Fingerprints
wpbot_conversation_boxqc-chatbot-popupwpbot-headerwpbot-message-containerwpbot-input-container<!-- Plugin Name: AI ChatBot - WPBot --><!-- Plugin URI: https://wordpress.org/plugins/chatbot/ --><!-- Author: QuantumCloud --><!-- Author URI: https://www.wpbot.pro/ -->+8 moredata-wpbot-urldata-wpbot-imagedata-wpbot-titledata-wpbot-placeholderdata-wpbot-welcome-messagedata-wpbot-ai-model+20 morewpbot_paramsQCqcld_wb_chatbot_objQCLD_wpCHATBOT_VERSIONQCLD_wpCHATBOT_PLUGIN_URLQCLD_wpCHATBOT_IMG_URL+3 more/wp-json/wpbot/v1/get_response/wp-json/wpbot/v1/get_user_history/wp-json/wpbot/v1/send_message