WordPress Plugin Vulnerabilities

Chat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OTP Bypass

Description

The plugin does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS one-time-password password reset is enabled.

Proof of Concept

Affects Plugins

Fixed in 1.0.9

References

Classification

Miscellaneous

Original Researcher
moonge
Submitter
moonge
Verified
Yes

Timeline

Publicly Published
2026-07-17 (about 1 month ago)
Added
2026-07-17 (about 1 month ago)
Last Updated
2026-08-21 (about 2 days ago)

Other