CVE-2024-9686

The Order Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing capability check on the 'nktgnfw_send_test_message' function in versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers to send a test message via the Telegram Bot API to the user configured in the settings.
Configurations

Configuration 1 (hide)

cpe:2.3:a:choplugins:order_notification_for_telegram:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2024-10-25 05:15

Updated : 2024-11-06 16:19


NVD link : CVE-2024-9686

Mitre link : CVE-2024-9686

CVE.ORG link : CVE-2024-9686


JSON object : View

Products Affected

choplugins

  • order_notification_for_telegram
CWE
CWE-862

Missing Authorization