Impact
The vulnerability is a Missing Authorization flaw in the Cliengo – Chatbot WordPress plugin. It allows an attacker to exploit incorrectly configured access control levels to access functionalities that should be restricted to authenticated users. The primary consequence is that a non‑authenticated user could potentially view or alter chatbot settings, undermining confidentiality and integrity of the plugin configuration. The weakness is identified as CWE‑862.
Affected Systems
WordPress sites using the Cliengo – Chatbot plugin version 3.0.4 or earlier are affected. The vendor is cliengo, with the product named Cliengo – Chatbot. No later versions are impacted. Administrators should verify the installed plugin version and apply updates accordingly.
Risk and Exploitability
The CVSS score of 6.5 places the issue in the moderate severity range. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, through web requests to the plugin’s endpoints, as the flaw stems from missing authorization checks. While exploitation risk is moderate, a successful attack would lift unauthorized control over the plugin, potentially exposing sensitive configuration data or enabling further escalation if other vulnerabilities exist.
OpenCVE Enrichment