What the vulnerability does
01Description
The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_update_options function in versions up to, and including, 1.5. This flaw makes it possible for low-level authenticated attackers to connect their own Facebook Messenger account to any site running the vulnerable plugin and engage in chats with site visitors on affected sites.
Explanation of Vulnerability in Simple Terms
02Summary
The Facebook Chat Plugin for WordPress versions before 1.6 does not properly restrict access to certain functions based on user roles. A logged-in user with low privileges can read, modify, or delete data belonging to other users or the site itself. The vulnerability affects the plugin's core chat and configuration features.
What an attacker can do
03Attacker Capabilities
Read, modify, or delete other users' data and site settings without proper authorization.
Potential impact on your site
04Site Impact
Unauthorized users can access private messages, change plugin settings, or disrupt chat functionality for legitimate users.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress account (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
October 16, 2024
CVE published
April 8, 2026
Record updated