The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handler. This is due to the wpcs_send_email() function being registered on both wp_ajax_wpcs_send_email and wp_ajax_nopriv_wpcs_send_email with no nonce verification, capability check, or rate limiting, while forwarding attacker-controlled recipient, subject, and body directly to wp_mail(). This makes it possible for unauthenticated attackers to send arbitrary emails to any recipient from the site's domain, enabling spam, phishing, and abuse that can lead to the site's IP/domain being blacklisted.
We have discovered 1,009 live websites that are affected by CVE-2026-16774.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,009 live websites (100% of Chatbot install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 150 versions ( 100% of all versions) |
| 330 websites | |
| 71 websites | |
| 62 websites | |
| 52 websites | |
| 39 websites | |
| 37 websites | |
| 34 websites | |
| 28 websites | |
| 24 websites | |
| 23 websites |
| .com | 476 websites |
| .org | 45 websites |
| .net | 33 websites |
| .it | 23 websites |
| .com.au | 23 websites |
| .co.uk | 22 websites |
| .de | 17 websites |
| .fr | 16 websites |
| .ca | 15 websites |
| .eu | 11 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.****.br | **,*** | ||
| ****.***.mt | **,*** | ||
| ************.org | **,*** | ||
| ****.***.my | ***,*** | ||
| ***.international | ***,*** | ||
| ************.com | ***,*** | ||
| ***.**.ke | ***,*** | ||
| **********.com | ***,*** | ||
| ****.info | ***,*** | ||
| ****.com | ***,*** |
FAQ