CVE-2021-24914
The Tawk.To Live Chat plugin before version 0.6.0 contains two AJAX actions lacking proper permission validation and CSRF protection that can be exploited by any logged-in user. An authenticated attacker with subscriber-level access or higher can manipulate the tawkto_setwidget action to redirect the live chat functionality to their own Tawk.to account, enabling them to monitor visitor interactions and display custom knowledge bases on the affected site. Additionally, the tawkto_removewidget action allows any authenticated user to disable the live chat widget entirely from the website's pages.
Based on public CVE data (MITRE/NVD).