Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50064 | The TeploBot - Telegram Bot for WP plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'service_process' function in all versions up to, and including, 1.3. This makes it possible for unauthenticated attackers to view the Telegram Bot Token, which is a secret token to control the bot. |
Fri, 25 Oct 2024 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Te-st teplobot
|
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:te-st:teplobot:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Te-st teplobot
|
Tue, 22 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Te-st
Te-st teplobot Telegram Bot For Wp |
|
| CPEs | cpe:2.3:a:te-st:teplobot_telegram_bot_for_wp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Te-st
Te-st teplobot Telegram Bot For Wp |
|
| Metrics |
ssvc
|
Tue, 22 Oct 2024 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The TeploBot - Telegram Bot for WP plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'service_process' function in all versions up to, and including, 1.3. This makes it possible for unauthenticated attackers to view the Telegram Bot Token, which is a secret token to control the bot. | |
| Title | TeploBot - Telegram Bot for WP <= 1.3 - Telegram Bot Token Disclosure | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:34:24.219Z
Reserved: 2024-10-08T13:01:26.181Z
Link: CVE-2024-9627
Updated: 2024-10-22T14:22:27.869Z
Status : Analyzed
Published: 2024-10-22T07:15:02.687
Modified: 2024-10-25T21:19:48.757
Link: CVE-2024-9627
No data.
OpenCVE Enrichment
No data.
EUVD