Input validation vulnerability in Cliengo – Chatbot 3.0.1

A popular plugin called Cliengo – Chatbot for WordPress has a security issue. This means that anyone who uses the plugin, up to version 3.0.1, may be vulnerable to an attack. The problem is that the plugin does not properly check for a security code, called a nonce, when performing a certain function. This could allow attackers who are not logged in to the website to trick the website administrator into doing something they should not.

Detected in:

Cliengo – Chatbot fixed vulnerable versions: >= * <= 3.0.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.