PatchSiren

WPBot CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review WPBot CVE published 2026-07-27

CVE-2026-14189

The WPBot WordPress plugin before 8.5.2 has a SQL injection vulnerability. Users with administrator access can perform SQL injection that executes when a visitor triggers a search. This vulnerability allows attackers to inject malicious SQL code, potentially leading to data breaches or site compromise. Administrators of WordPress sites using the WPBot plugin should update to version 8.5.2 or later to prev [truncated]