CVE-2024-12541
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-12541 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Chative Live chat and Chatbot plugin for WordPress. Versions up to 1.1 are susceptible to this issue. The root cause is a missing or incorrect nonce validation on the add_chative_widget_action() function. An attacker can exploit this vulnerability by tricking a site administrator into performing an action, such as clicking on a malicious link. Successful exploitation enables the attacker to change the channel ID or organization ID, potentially redirecting the live chat widget to an attacker-controlled channel.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.