[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLbAVmJi1hV9sVNCFp2gU71q3OQSx4tNgOoANpdcFm4o":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20,"patch_diff_files":21,"patch_trac_url":9,"research_status":27,"research_verified":28,"research_rounds_completed":29,"research_plan":30,"research_summary":9,"research_vulnerable_code":9,"research_fix_diff":9,"research_exploit_outline":9,"research_model_used":31,"research_started_at":32,"research_completed_at":33,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":28,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":28,"source_links":34},"CVE-2026-57414","ai-chatbot-for-ecommerce-woowbot-authenticated-subscriber-stored-cross-site-scripting","AI ChatBot for eCommerce – WoowBot \u003C= 4.6.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting","The AI ChatBot for eCommerce – WoowBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","woowbot-woocommerce-chatbot",null,"\u003C=4.6.1","4.7.0","medium",6.4,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:C\u002FC:L\u002FI:L\u002FA:N","Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","2026-07-08 00:00:00","2026-07-14 19:25:36",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fa1d5c661-ebaf-4752-8263-ce6dc2f355cd?source=api-prod",7,[22,23,24,25,26],"css\u002Fadmin-style.css","css\u002Ffrontend-style.css","css\u002Fwoo-chatbot-tabs.css","functions.php","js\u002Fqcld-woo-chatbot-admin.js","researched",false,3," \u003Cscript>alert(1)\u003C\u002Fscript>`.\n    If the plugin has a \"Help\" or \"Support\" message that is echoed on the frontend *without* escaping.\n    Let's check the `functions.php` for any other `get_option`.\n    I see `qlcd_woo_chatbot_conversations_with` and `qlcd_woo_chatbot_agent`.\n    If the vulnerability is that a Subscriber can call `wp_ajax_qcld_woo_chatbot_save_settings` (inferred) and update these.\n    Wait, I see a potential mismatch in the provided `functions.php`.\n    ```php\n    \u003Ch3> \u003C?php if(get_option('qlcd_woo_chatbot_agent')!=''){echo esc_attr( get_option('qlcd_woo_chatbot_agent') );} ?>\u003C\u002Fh3>\n    ```\n    If I change `qlcd_woo_chatbot_agent` to `\u003C\u002Fscript>\u003Cscript>alert(1)\u003C\u002Fscript>`, `esc_attr` handles it.\n    *But*, what if I change `woo_chatbot_custom_css`?\n    If I change it to `body{} \u003C\u002Fstyle>\u003Cscript>alert(1)\u003C\u002Fscript>\u003Cstyle>`.\n    `esc_attr` converts `\u003C` to `&lt;`.\n    The resulting HTML: `\u003Cstyle>body{} &lt;\u002Fstyle&gt;&lt;script&gt;alert(1)&lt;\u002Fscript&gt;&lt;style&gt;\u003C\u002Fstyle>`.\n    ","gemini-3-flash-preview","2026-07-16 15:11:41","2026-07-16 15:13:22",{"type":35,"vulnerable_version":36,"fixed_version":11,"vulnerable_browse":37,"vulnerable_zip":38,"fixed_browse":39,"fixed_zip":40,"all_tags":41},"plugin","4.6.1","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwoowbot-woocommerce-chatbot\u002Ftags\u002F4.6.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwoowbot-woocommerce-chatbot.4.6.1.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwoowbot-woocommerce-chatbot\u002Ftags\u002F4.7.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwoowbot-woocommerce-chatbot.4.7.0.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwoowbot-woocommerce-chatbot\u002Ftags"]