Unauthenticated Disclosure of Sensitive Information in TeploBot for WordPress
CVE-2024-9627
7.3HIGH
What is CVE-2024-9627?
The TeploBot - Telegram Bot for WP plugin for WordPress has a vulnerability that affects its 'service_process' function, where lack of sufficient authorization checks can lead to the unintended exposure of sensitive information. Specifically, unauthenticated users can gain access to the Telegram Bot Token, a crucial secret that enables control over the bot. This issue poses significant security risks, as the exposed token may allow malicious actors to manipulate or hijack the bot's operations.