The friendly little AI chatbot in the corner of a website has a job, and to do it, it keeps two things: a key to the AI service behind it, and the business's real contact channels. On a lot of sites, both were sitting in a drawer anyone on the internet could open. No login. No trick. Just knowing which drawer to pull.
This week, two findings from one company, QuantumCloud. In SiteLeads, a lead-and-chat widget, all the settings — the AI key, the phone, the email, the Telegram — were quietly published to the open web, readable by anyone. Reported through Patchstack, fixed in the next release, and on the public record as CVE-2026-78268, credited to LevinityCyber. In their other chatbot plugin, WoowBot, the opposite door was open: a missing check let any logged-in user change the plugin's settings.
We get into what a leaked AI key is actually worth, and the one idea underneath it all: storing something and locking something are two different jobs, and the second one keeps getting skipped. QuantumCloud handled both the right way — fixed fast, and cleared us to tell the story.
Chapters
(0:00) Cold open — the front desk with the unlocked drawer
(2:00) Every AI helper holds two secrets
(4:17) The SiteLeads leak — one address, no login
(6:14) WoowBot — same vendor, the opposite door
(8:34) What it's actually worth to an attacker
(12:05) Why this keeps happening — AI keys are the new passwords
(15:24) What to do tonight (check your own site)
(18:28) Outro
What to do tonight: if there's an AI helper on your site, find out what it is and update it. If you build software, never store a secret anywhere that can be published, and put the lock in the code, not in the label. And treat every AI key like the password it is.
Evidence, or it doesn't count.
Links
CVE-2026-78268: cve.org/CVERecord?id=CVE-2026-78268
SiteLeads writeup: levinitycyber.com/research/siteleads-unauthenticated-sensitive-data-exposure
WoowBot writeup: levinitycyber.com/research/woowbot-woocommerce-missing-authorization
Disclosure wall: levinitycyber.com/research
Levinity Cyber: levinitycyber.com
#CyberSecurity #InfoSec #AppSec #AISecurity #WordPress #WordPressSecurity #APISecurity #AIChatbot #DataLeak #ResponsibleDisclosure #CVE #BugBounty #SecurityPodcast #LevinityCyber