CVE-2024-9627

The TeploBot - Telegram Bot for WP plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'service_process' function in all versions up to, and including, 1.3. This makes it possible for unauthenticated attackers to view the Telegram Bot Token, which is a secret token to control the bot.
Configurations

Configuration 1 (hide)

cpe:2.3:a:te-st:teplobot:*:*:*:*:*:wordpress:*:*

History

25 Oct 2024, 21:19

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/browser/green-wp-telegram-bot-by-teplitsa/trunk/inc/core.php?rev=1754863#L266 - () https://plugins.trac.wordpress.org/browser/green-wp-telegram-bot-by-teplitsa/trunk/inc/core.php?rev=1754863#L266 - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/091dadcb-71ac-4321-b3aa-72b5fbbd9163?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/091dadcb-71ac-4321-b3aa-72b5fbbd9163?source=cve - Third Party Advisory
First Time Te-st
Te-st teplobot
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : 8.6
v2 : unknown
v3 : 7.3
CPE cpe:2.3:a:te-st:teplobot:*:*:*:*:*:wordpress:*:*

23 Oct 2024, 15:12

Type Values Removed Values Added
Summary
  • (es) El complemento TeploBot - Telegram Bot for WP para WordPress es vulnerable a la divulgación de información confidencial debido a la falta de comprobaciones de autorización en la función 'service_process' en todas las versiones hasta la 1.3 incluida. Esto hace posible que atacantes no autenticados vean el token del bot de Telegram, que es un token secreto para controlar el bot.

22 Oct 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-22 07:15

Updated : 2024-10-25 21:19


NVD link : CVE-2024-9627

Mitre link : CVE-2024-9627

CVE.ORG link : CVE-2024-9627


JSON object : View

Products Affected

te-st

  • teplobot
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor