A vulnerability was found in quantumcloud WPBot Plugin up to 8.5.9 on WordPress. It has been classified as critical. This impacts the function
wpcs_send_email of the component AJAX Handler. The manipulation of the argument recipient/subject/body leads to improper authorization.
This vulnerability is listed as CVE-2026-16774. The attack may be initiated remotely. There is no available exploit.