What is CVE-2026-16773?
A Sensitive Information Exposure vulnerability exists in the WPBot plugin for WordPress up to version 8.5.9, allowing unauthenticated attackers to exfiltrate full chat transcripts via the `wpbot_send_email_transcript_free` function. Users should update the plugin to the latest patched version immediately.
Azərbaycanca: WordPress üçün WPBot plaqininin 8.5.9 versiyasına qədər olan versiyalarında həssas məlumat ifşası zəifliyi aşkarlanıb. Bu, autentifikasiya olunmamış hücumçulara `wpbot_send_email_transcript_free` funksiyası vasitəsilə tam çat transkriptlərini əldə etməyə imkan verir. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which function in the WPBot plugin is exploited for the sensitive information exposure in CVE-2026-16773?
The vulnerability allows unauthenticated attackers to exfiltrate full chat transcripts via the `wpbot_send_email_transcript_free` function.
What should WPBot users do to mitigate CVE-2026-16773?
Users should update the WPBot plugin to the latest patched version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.