CVE-2020-36838: Facebook Chat Plugin <= 1.5 - Missing Capabilities Check
The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wpajaxupdateoptions function in versions up to, and including, 1.5. This flaw makes it possible for low-level authenticated attackers to connect their own Facebook Messenger account to any site running the vulnerable plugin and engage in chats with site visitors on affected sites.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36838?
CVE-2020-36838 has a moderate severity level due to its potential for unauthorized access.
How do I fix CVE-2020-36838?
To fix CVE-2020-36838, update the Facebook Chat Plugin for WordPress to version 1.6 or higher.
Who is affected by CVE-2020-36838?
CVE-2020-36838 affects users of the Facebook Chat Plugin for WordPress up to version 1.5.
What is the nature of the vulnerability in CVE-2020-36838?
CVE-2020-36838 is an authorization bypass vulnerability that allows low-level authenticated attackers to exploit the wp_ajax_update_options function.
What are the implications of CVE-2020-36838 for website security?
CVE-2020-36838 could allow attackers to impersonate other users or alter chat configurations, compromising website security.