Cross-Site Request Forgery and XSS Vulnerabilities in Acobot Live Chat & Contact Form for WordPress
CVE-2015-2039
Currently unrated
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 20 February 2015
What is CVE-2015-2039?
The Acobot Live Chat & Contact Form plugin for WordPress contains multiple vulnerabilities, allowing remote attackers to exploit CSRF weaknesses. By strategically crafting requests, an attacker can hijack the authentication of administrators. This manipulation can lead to unauthorized changes in plugin settings and facilitate cross-site scripting (XSS) attacks through the acobot_token parameter, posing significant risks to the security and integrity of affected WordPress sites.