PT-2026-26802 · Atomchat · Group Chat & Video Chat By Atomchat

Nabil Irawan

·

Published

2026-03-21

·

Updated

2026-03-21

·

CVE-2026-1253

CVSS v3.1

5.3

Medium

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'atomchat update auth ajax' and 'atomchat update layout ajax' functions in all versions up to, and including, 1.1.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update plugin options, including critical settings such as API keys, authentication keys, and layout configurations.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-1253

Affected Products

Group Chat & Video Chat By Atomchat