Beta

Report

Cliengo – Chatbot <= 3.0.1 is vulnerable to WordPress Cliengo - Chatbot plugin <= 3.0.1 - Missing Authorization to Authorized (Subscriber+) Chatbot Settings Update vulnerability

Subscriber
Published
2024-07-08

The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_session' function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the session token of the chatbot.

CVSS

Score:5.4

Severity:Medium

Version: 3.0.1

The plugin vendor has not patched this vulnerability at the moment.