Vulnerabilities > Tawk

DATE CVE VULNERABILITY TITLE RISK
2021-12-06 CVE-2021-24914 Cross-Site Request Forgery (CSRF) vulnerability in Tawk Tawk.To Live Chat
The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and tawkto_removewidget AJAX actions, available to any authenticated user.
network
low complexity
tawk CWE-352
8.0