Access Control Vulnerability in alexvtn Chatbox Manager by WordPress
CVE-2025-30790

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 March 2025

What is CVE-2025-30790?

The alexvtn Chatbox Manager is susceptible to an access control issue that allows unauthorized users to access functionalities that should be restricted. This vulnerability stems from improper constraints on Access Control Lists (ACLs), enabling users to perform actions without proper permission checks. Affected versions include all versions up to 1.2.2, and it is essential for users to take immediate action to secure their installations against potential exploitation.

Affected Version(s)

Chatbox Manager <= 1.2.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan (Patchstack Alliance)
.