Sceawere

Vulnerability Detail

CVE-2026-39730UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Wise Chat Subscriber Access Control

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
16h ago
Vendor
Marcin
Product
Wise Chat
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Attack Complexity
LOW

Narrative and Response

Description

Subscriber Broken Access Control in Wise Chat <= 3.4.1 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-06T09:17:45.433Z",
  "pubdate": "2026-10-06T09:17:45.433Z",
  "executiveSummary": "The Wise Chat plugin for WordPress, in versions up to and including 3.4.1, contains a vulnerability involving broken access control.\nThis flaw allows authenticated users with low-level privileges, such as Subscribers, to perform actions or access data restricted to higher-privileged users, such as Administrators.\nThe vulnerability type is categorized as Improper Access Control, which facilitates unauthorized operations due to a failure in validating the user's role before executing privileged functions.\nThe impact includes potential unauthorized data access, unauthorized configuration modifications, or the exploitation of administrative features that the attacker should not have permission to invoke.\nAn attacker must be authenticated as a registered user (e.g., Subscriber) on the vulnerable WordPress site to leverage this vulnerability, meaning exploitation is not possible for unauthenticated remote attackers.\nThis represents a significant security risk, as it violates the principle of least privilege, allowing users to exceed their intended functional scope within the application.",
  "technicalDetails": "The vulnerability resides within the access control mechanisms implemented in Wise Chat versions 3.4.1 and below. The root cause is the inadequate verification of user capabilities or roles prior to processing requests that trigger administrative or sensitive actions.\nIn WordPress, plugin developers are responsible for ensuring that functions performing administrative tasks or accessing sensitive data perform an explicit capability check (e.g., using current_user_can()) to confirm the user has the necessary permissions.\nThe attack flow begins when an attacker, authenticated with a low-privileged account such as a Subscriber, identifies a specific URL endpoint or AJAX action within the Wise Chat plugin that should be restricted.\nBy crafting a request targeted at these sensitive endpoints—often involving POST or GET parameters that trigger specific plugin functions—the attacker can bypass the intended authorization checks. Because the plugin fails to validate the user's role, the application treats the request as legitimate, allowing the Subscriber to execute functions designed only for administrative users.\nThe vulnerable component involves the server-side processing of plugin-specific requests. If the plugin's action handlers do not incorporate robust nonce verification combined with strict capability checks, it allows for unauthorized interaction with the plugin's backend logic.\nThe exploitation method involves sending an HTTP request directly to the vulnerable plugin action endpoint while maintaining an active, low-privileged user session. The server-side code executes the requested function under the security context of the user, but since the authorization logic is flawed or missing, the restricted action proceeds.\nPost-exploitation impact varies depending on the specific functions exposed through this broken access control. This could range from the modification of chat settings, deletion of chat history, potential manipulation of user data, or unauthorized interactions that could disrupt the service or compromise data integrity within the context of the chat plugin."
}
CVE-2026-39730: Wise Chat Subscriber Access Control (HIGH Severity, CVSS: 7.1) | Sceawere