Description
Missing Authorization vulnerability in alexvtn Chatbox Manager wa-chatbox-manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Chatbox Manager: from n/a through <= 1.2.2.
Published: 2025-03-27
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing authorization in the Chatbox Manager plugin allows users to exploit functionality that is not properly protected by access‑control lists. The vulnerability permits an attacker to invoke privileged operations such as creating, editing, or deleting chat widgets, changing configuration settings, or retrieving stored messages. Because the plugin runs within a WordPress site, successful exploitation could lead to data confidentiality breaches, integrity violations, and potentially elevate control over the site’s administrative interface.

Affected Systems

The flaw affects the alexvtn Chatbox Manager WordPress plugin on all installations from the earliest release through version 1.2.2. Any WordPress site that has this plugin enabled and has a user role capable of interacting with the plugin’s endpoints is at risk.

Risk and Exploitability

The CVSS score of 5.3 denotes moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attacks would most likely be carried out by sending crafted HTTP requests to the plugin’s privileged endpoints, potentially using an existing user session or by discovering publicly accessible URLs. The lack of strict ACL checks means that anyone who can reach the endpoint could gain unauthorized control, making the vulnerability particularly concerning for sites with exposed or weak credentials.

Generated by OpenCVE AI on May 1, 2026 at 04:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Chatbox Manager plugin to the latest release that addresses the access‑control flaw; if no update is available, remove or disable the plugin entirely.
  • Configure WordPress role capabilities so that only administrators can access plugin management pages; apply a site‑wide security plugin to enforce role‑based access controls.
  • Monitor site logs for unusual plugin activity or repeated access attempts to the plugin’s admin URLs, and block suspicious IP addresses or user agents.

Generated by OpenCVE AI on May 1, 2026 at 04:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8370 Missing Authorization vulnerability in alexvtn Chatbox Manager allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Chatbox Manager: from n/a through 1.2.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in alexvtn Chatbox Manager allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Chatbox Manager: from n/a through 1.2.2. Missing Authorization vulnerability in alexvtn Chatbox Manager wa-chatbox-manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Chatbox Manager: from n/a through <= 1.2.2.
Title WordPress Chatbox Manager <= 1.2.2 - Broken Access Control Vulnerability WordPress Chatbox Manager plugin <= 1.2.2 - Broken Access Control Vulnerability
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Thu, 27 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 11:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in alexvtn Chatbox Manager allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Chatbox Manager: from n/a through 1.2.2.
Title WordPress Chatbox Manager <= 1.2.2 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:57.420Z

Reserved: 2025-03-26T09:20:11.232Z

Link: CVE-2025-30790

cve-icon Vulnrichment

Updated: 2025-03-27T13:59:58.190Z

cve-icon NVD

Status : Deferred

Published: 2025-03-27T11:15:40.357

Modified: 2026-04-23T15:27:04.493

Link: CVE-2025-30790

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T04:15:08Z

Weaknesses