The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_chatbot_token' and 'update_chatbot_position' functions in all versions up to, and including, 3.0.1. This makes it possible for unauthenticated attackers to change chatbot settings, which can lead to unavailability or other changes to the chatbot.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47108 | The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_chatbot_token' and 'update_chatbot_position' functions in all versions up to, and including, 3.0.1. This makes it possible for unauthenticated attackers to change chatbot settings, which can lead to unavailability or other changes to the chatbot. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-01T21:25:03.186Z
Reserved: 2024-06-13T21:55:11.318Z
Link: CVE-2024-5992
Updated: 2024-08-01T21:25:03.186Z
Status : Awaiting Analysis
Published: 2024-07-09T09:15:08.727
Modified: 2024-11-21T09:48:42.750
Link: CVE-2024-5992
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:22:42Z
Weaknesses
No weakness.
EUVD