Beta

Report

TeploBot - Telegram Bot for WP <= 1.3 is vulnerable to WordPress TeploBot - Telegram Bot for WP plugin <= 1.3 - Telegram Bot Token Disclosure vulnerability

Unauthenticated
Published
2024-10-20

The TeploBot - Telegram Bot for WP plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'service_process' function in all versions up to, and including, 1.3. This makes it possible for unauthenticated attackers to view the Telegram Bot Token, which is a secret token to control the bot.

CVSS

Score:7.5

Severity:High

Version: 1.3

The plugin vendor has not patched this vulnerability at the moment.