---
id: CVE-2026-15241
title: >-
  The AI ChatBot for WooCommerce  WordPress plugin before 4.8.4 does not perform
  any authorization or nonce check on one of its AJAX actions, allowing
  unauthenticated users to abuse the site owner's stored third-party API key to
  send reque…
summary: >-
  The AI ChatBot for WooCommerce  WordPress plugin before 4.8.4 does not perform
  any authorization or nonce check on one of its AJAX actions, allowing
  unauthenticated users to abuse the site owner's stored third-party API key to
  send reque…
severity: none
published: '2026-08-02'
updated: '2026-08-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15241'
references:
  - url: 'https://wpscan.com/vulnerability/81ab9ecd-5d7b-4d10-b255-65af869c46e2/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-08-02T13:18:29.090Z'
epss: 0.00406
epssPercentile: 0.32204
---

## Overview

The AI ChatBot for WooCommerce  WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to retrieve indexed knowledge-base content.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
