Description
WordPress Plugin The Official Facebook Chat is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently update plugin's options and hook-up their own Facebook Messenger account and engage in chats with site visitors. WordPress Plugin The Official Facebook Chat version 1.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.6 or latest
References
Related Vulnerabilities
Squid Improper Input Validation Vulnerability (CVE-2014-3609)
ZenCart Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-11675)
Undertow Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2017-2670)
WordPress Plugin Easy Table Cross-Site Scripting (1.5.2)
Oracle Application Server CVE-2008-2614 Vulnerability (CVE-2008-2614)