Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-36838

Опубликовано: 16 окт. 2024
Источник: nvd
CVSS3: 7.4
EPSS Низкий

Описание

The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_update_options function in versions up to, and including, 1.5. This flaw makes it possible for low-level authenticated attackers to connect their own Facebook Messenger account to any site running the vulnerable plugin and engage in chats with site visitors on affected sites.

EPSS

Процентиль: 6%
0.00023
Низкий

7.4 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.4
github
больше 1 года назад

The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_update_options function in versions up to, and including, 1.5. This flaw makes it possible for low-level authenticated attackers to connect their own Facebook Messenger account to any site running the vulnerable plugin and engage in chats with site visitors on affected sites.

EPSS

Процентиль: 6%
0.00023
Низкий

7.4 High

CVSS3

Дефекты

CWE-284