CVE-2026-15241 Details
Description
The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to retrieve indexed knowledge-base content.
A vulnerability exists in the AI ChatBot for WooCommerce WordPress plugin in versions prior to 4.8.4. The issue arises because the plugin's AJAX actions lack proper authorization and nonce checks. This flaw enables unauthenticated users to misuse the site owner's third-party API key, sending requests charged to the owner's account. Additionally, if a certain optional feature is activated, it allows the retrieval of indexed knowledge-base content.
Users are advised to update the AI ChatBot for WooCommerce WordPress plugin to version 4.8.4 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 2, 2026CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/81ab9ecd-5d7b-4d10-b255-65af869c46e2/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| AI ChatBot for WooCommerce | < 4.8.4 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 2, 2026 | New CVE Received | [email protected] |
Volerion