CVE · High

CVE-2021-24914 — Tawk.To Live Chat [tawkto-live-chat] < 0.6.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24914 Tawk.To Live Chat [tawkto-live-chat] < 0.6.0 Cross-Site Request Forgery (CSRF) High 8.0 < 0.6.0 0.6.0 2021-11-08

CVE-2021-24914

The Tawk.To Live Chat plugin before version 0.6.0 contains two AJAX actions lacking proper permission validation and CSRF protection that can be exploited by any logged-in user. An authenticated attacker with subscriber-level access or higher can manipulate the tawkto_setwidget action to redirect the live chat functionality to their own Tawk.to account, enabling them to monitor visitor interactions and display custom knowledge bases on the affected site. Additionally, the tawkto_removewidget action allows any authenticated user to disable the live chat widget entirely from the website's pages.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.