WordPress Plugin Vulnerabilities

One to one user Chat by WPGuppy < 1.1.1 - Authorization Bypass

Description

The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.0. This is due to the plugin not properly verifying a user's identity prior to using wp_set_current_user(). This makes it possible for unauthenticated attackers to spoof other users and modify some of the plugin's settings.

Affects Plugins

Fixed in 1.1.1

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
l8BL
Verified
No

Timeline

Publicly Published
2025-01-09 (about 1 year ago)
Added
2025-02-24 (about 1 year ago)
Last Updated
2025-02-24 (about 1 year ago)

Other