What is CVE-2026-15241?
The AI ChatBot for WooCommerce plugin (before version 4.8.4) lacks authorization and nonce checks on an AJAX action, enabling unauthenticated users to abuse the site owner's third-party API key for billed requests. Upgrading to version 4.8.4 or later is recommended.
Azərbaycanca: CVE-2026-15241: AI ChatBot for WooCommerce plaqinində (4.8.4-dən əvvəl) authorizasiya yoxlanışı olmadığı üçün autentifikasiya olunmamış istifadəçilər AJAX əməliyyatı vasitəsilə sayt sahibinin üçüncü tərəf API açarını sui-istifadə edərək ödənişli sorğular göndərə bilər. Plaqini 4.8.4 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: WooCommerce
FAQ2
Which versions of AI ChatBot for WooCommerce does CVE-2026-15241 affect?
This vulnerability affects versions of the plugin before 4.8.4.
What can an unauthenticated user do via CVE-2026-15241?
An unauthenticated user can abuse the site owner's third-party API key to send billed requests via an AJAX action.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.