CVE-2024-9627
22.10.2024, 07:15
The TeploBot - Telegram Bot for WP plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'service_process' function in all versions up to, and including, 1.3. This makes it possible for unauthenticated attackers to view the Telegram Bot Token, which is a secret token to control the bot.Enginsight
Vendor | Product | Version |
---|---|---|
te-st | teplobot_telegram_bot_for_wp | 𝑥 ≤ 1.3 |
te-st | teplobot | 𝑥 ≤ 1.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration