What is CVE-2026-16774?
CVE-2026-16774 is a Missing Authorization vulnerability in the Chatbot plugin for WordPress up to version 8.5.9, allowing unauthenticated attackers to send emails via the wpcs_send_email() AJAX handler due to a missing nonce check. Users should update the plugin to the latest version.
Azərbaycanca: CVE-2026-16774 WordPress üçün Chatbot plagininin 8.5.9 və daha əvvəl versiyalarında wpcs_send_email() AJAX funksiyasında `nonce` yoxlaması olmaması səbəbindən icazəsiz əməliyyat zəifliyidir. Bu, autentifikasiya olunmamış hücumçulara e-poçt göndərməyə imkan verir. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Chatbot plugin are affected by CVE-2026-16774?
The Chatbot plugin for WordPress up to version 8.5.9 is vulnerable to this issue.
How can an attacker exploit this vulnerability?
Unauthenticated attackers can send unauthorized emails via the wpcs_send_email() AJAX handler due to a missing nonce check.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.