← Back

CVE-2024-9627

nvd nist
Published: Oct 22, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.4
Source: NVD

Description

The TeploBot - Telegram Bot for WP plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'service_process' function in all versions up to, and including, 1.3. This makes it possible for unauthenticated attackers to view the Telegram Bot Token, which is a secret token to control the bot.

Affected (1)

Products: Te St: Teplobot
1 product
Teplobot
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.3

Timeline

No history available yet.