CVE-2026-87959: The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI
Summary
The WPBot WordPress plugin (a tool that adds AI features to WordPress websites) before version 8.7.6 is missing a security check on one of its functions, allowing low-level users (subscribers) to change important settings including the API key (a secret credential used to access the Claude AI service). This means even basic users could potentially hijack the plugin's connection to the AI service.
Solution / Mitigation
Update WPBot WordPress plugin to version 8.7.6 or later.
Vulnerability Details
EPSS: 0.0%
September 16, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-87959
First tracked: September 16, 2026 at 08:08 AM
Classified by LLM (prompt v3) · confidence: 92%