The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the site's MobileMonkey API token and company ID options, which can be used to hijack chatbot configuration and redirect visitor conversations to an attacker-controlled MobileMonkey account.
Metrics
Affected Vendors & Products
References
History
Mon, 23 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Larrykim
Larrykim wp-chatbot For Messenger Wordpress Wordpress wordpress |
|
| Vendors & Products |
Larrykim
Larrykim wp-chatbot For Messenger Wordpress Wordpress wordpress |
Sat, 21 Mar 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the site's MobileMonkey API token and company ID options, which can be used to hijack chatbot configuration and redirect visitor conversations to an attacker-controlled MobileMonkey account. | |
| Title | WP-Chatbot for Messenger <= 4.9 - Missing Authorization to Unauthenticated Chatbot Configuration Takeover | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-03-21T03:26:39.802Z
Updated: 2026-03-23T18:05:30.321Z
Reserved: 2026-03-04T01:19:23.729Z
Link: CVE-2026-3506
Updated: 2026-03-23T18:05:20.554Z
Status : Awaiting Analysis
Published: 2026-03-21T04:17:27.390
Modified: 2026-03-23T14:32:02.800
Link: CVE-2026-3506
No data.