Facebook Chat Plugin <= 1.5 - Missing Capabilities Check
2020-08-04 00:00
Chloe ChamberlandStrategic Overview
StatusPatched in 1.6
Affected PluginFacebook Chat Plugin – Live Chat Plugin for WordPress
Affected Version
< 1.6CVSS7.4High
CVE
CVE-2020-36838Vulnerability Overview
The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_update_options function in versions up to, and including, 1.5. This flaw makes it possible for low-level authenticated attackers to connect their own Facebook Messenger account to any site running the vulnerable plugin and engage in chats with site visitors on affected sites.
Technical Analysis
REMEDIATION: Update to version 1.6, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C