nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-32499 CVE-2026-32499
CRITICAL
WordPress ChatBot plugin <= 7.7.9 - SQL Injection vulnerability
Record summary
CVE-2026-32499 has a selected CVSS score of 9.3 (critical).
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatBot chatbot allows Blind SQL Injection.This issue affects ChatBot: from n/a through <= 7.7.9.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 20, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 26, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Through <= 7.7.9 | affected |
| VulnCheck | Version data not supplied | ||
References
2patchstack.comvdb entry
https://patchstack.com/database/Wordpress/Plugin/chatbot/vulnerability/wordpress-chatbot-plugin-7-7-9-sql-injection-vulnerability?_s_id=cve