The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to retrieve indexed knowledge-base content.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-15241 affects the AI ChatBot for WooCommerce plugin versions before 4.8.4, exposing a critical authorization bypass in AJAX endpoints. The vulnerability stems from missing nonce validation and authentication checks, allowing unauthenticated attackers to invoke privileged actions. This directly impacts WordPress site owners by enabling threat actors to abuse stored third-party API credentials—potentially making unauthorized requests billed to the owner's account and exfiltrating sensitive knowledge-base content. Any WooCommerce installation using this plugin before version 4.8.4 is at risk, particularly those leveraging AI chatbot features with integrated API integrations.
While this CVE lacks direct MITRE ATT&CK technique mapping, Casky's security skills would detect the underlying attack patterns associated with Improper Access Control (CWE-284). Practitioners using Casky would identify indicators such as: suspicious AJAX requests originating from unauthenticated sessions, unusual API consumption patterns tied to third-party services, and anomalous access to knowledge-base endpoints without proper session tokens. Extended reasoning across Casky's 754 mapped skills would surface related defensive controls—including input validation monitoring, AJAX security auditing, and API key exposure detection—enabling teams to identify compromised environments and implement compensating controls before third-party billing fraud or data exfiltration occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-15241. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation