CVE-2024-9821
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-9821 is a vulnerability affecting the Bot for Telegram plugin on WooCommerce for WordPress. This issue allows authenticated attackers, with subscriber-level access and above, to gain sensitive information through missing authorization checks on the 'stm_wpcfto_get_settings' AJAX action. By exploiting this vulnerability, attackers can view the Telegram Bot Token, a secret token used to manage bots, which can be leveraged to log in as any existing user on the site, including administrators, if the attacker knows the targeted user's username, due to the Login with Telegram feature.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.