Chat On Desk <= 1.0.8 - Unauthenticated Two-Factor Authentication Bypass to Password Reset
mediumThe Chat On Desk Order Notifications – WooCommerce plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in all versions up to, and including, 1.0.8. This makes it possible for unauthenticated attackers to bypass an OTP and reset arbitrary users passwords.
- CVSS:
- 5.3
- Affected:
- up to 1.0.8
- Fixed in:
- 1.0.9
- Disclosed:
- Jul 17, 2026