WordPress Plugin Vulnerabilities

The Official WordPress Facebook Chat Plugin < 1.6 - Authenticated Options Change to Chat Takeover

Description

This flaw made it possible for low-level authenticated attackers to connect their own Facebook Messenger account to any site running the vulnerable plugin and engage in chats with site visitors on affected sites.

Proof of Concept

Affects Plugins

References

Classification

Type
ACCESS CONTROLS
CWE
CVSS

Miscellaneous

Original Researcher
Chloe Chamberland
Submitter
Chloe Chamberland
Submitter website
Submitter twitter
Verified
No

Timeline

Publicly Published
2020-08-04 (about 5 years ago)
Added
2020-08-04 (about 5 years ago)
Last Updated
2020-08-07 (about 5 years ago)

Other