PT-2026-26857 · Unknown+1 · Mobilemonkey+1

Kazuma Matsumoto

·

Published

2026-03-21

·

Updated

2026-03-21

·

CVE-2026-3506

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP-Chatbot for Messenger plugin for WordPress versions prior to 4.9
Description The WP-Chatbot for Messenger plugin for WordPress is susceptible to an authorization bypass. The plugin does not adequately verify user authorization, allowing unauthenticated attackers to overwrite the site’s MobileMonkey API token and company ID options. Successful exploitation can lead to hijacking chatbot configuration and redirecting visitor conversations to an attacker-controlled MobileMonkey account.
Recommendations Update the WP-Chatbot for Messenger plugin to a version newer than 4.9.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3506

Affected Products

Mobilemonkey
Wp-Chatbot For Messenger