# CVE-2026-87918

## Summary

- **CVE ID:** CVE-2026-87918
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **CWE:** N/A
- **Published:** Sep 12, 2026
- **Last Modified:** Sep 12, 2026

## Description

The WPBot  WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attackers to make those third-party API calls, and consume the associated cost, using the site's own configured API keys.

## Affected Products

- Unknown — WPBot (0)

## References

- [CNA](https://wpscan.com/vulnerability/d6b3745b-bda1-4734-b39c-75376477ba0a/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.19%
- **EPSS Percentile:** 9.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._