CVE-2026-13731

HIGH EXPLOITED NUCLEI

WPBot <= 8.4.9 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-13731 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including HermesNA-1. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-13731, a stored XSS vulnerability in the WPBot WordPress plugin (versions up to 8.4.9). The code includes metadata and a placeholder `run()` method but lacks actual exploit implementation, referencing only WordPress plugin code paths for further research.

Description

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conversation' parameter in all versions up to, and including, 8.4.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The AJAX nonce required to authenticate the save request is publicly emitted on every frontend page via wp_localize_script, making it freely obtainable by any anonymous visitor and removing any practical barrier to exploitation.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2026-13731_the_wpbot.py

This repository contains an auto-generated stub module for CVE-2026-13731, a stored XSS vulnerability in the WPBot WordPress plugin (versions up to 8.4.9). The code includes metadata and a placeholder `run()` method but lacks actual exploit implementation, referencing only WordPress plugin code paths for further research.

Classification
Stub 99%
Attack Type
Xss
Complexity
Moderate
Reliability
Theoretical
Target: WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress (versions up to and including 8.4.9)
No auth needed
Prerequisites: Target must have the vulnerable WPBot plugin installed (≤8.4.9) · Attacker must be able to send crafted input to the 'conversation' parameter
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

Nuclei Templates (1)

WPBot <= 8.4.9 - Cross-Site Scripting
HIGHVERIFIEDby 0x_Akoko
Shodan: http.html:"wp_chatbot_obj"
FOFA: body="wp_chatbot_obj"

Scores

CVSS v3 7.2
EPSS 0.0066
EPSS Percentile 47.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

VulnCheck KEV 2026-07-01
CWE
CWE-79
Status published
Products (1)
quantumcloud/WPBot – AI ChatBot for Live Support, Lead Generation, AI Services < 8.4.9
Published Jul 01, 2026
Tracked Since Jul 01, 2026