PT-2026-26857 · Unknown+1 · Mobilemonkey+1

Kazuma Matsumoto

·

Publicado

2026-03-21

·

Atualizado

2026-03-21

·

CVE-2026-3506

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP-Chatbot for Messenger plugin for WordPress versions prior to 4.9
Description The WP-Chatbot for Messenger plugin for WordPress is susceptible to an authorization bypass. The plugin does not adequately verify user authorization, allowing unauthenticated attackers to overwrite the site’s MobileMonkey API token and company ID options. Successful exploitation can lead to hijacking chatbot configuration and redirecting visitor conversations to an attacker-controlled MobileMonkey account.
Recommendations Update the WP-Chatbot for Messenger plugin to a version newer than 4.9.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3506

Produtos afetados

Mobilemonkey
Wp-Chatbot For Messenger