3Cx Live Chat vulnerabilities
13 known vulnerabilities affecting 3cx/live_chat.
Total CVEs
13
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL3MEDIUM10
Vulnerabilities
Page 1 of 1
CVE-2019-14950P2MEDIUMCVSS 6.1ExploitedPoCfixed in 8.0.272019-08-12
CVE-2019-14950 [MEDIUM] CWE-79 CVE-2019-14950: The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.
The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.
nvd
CVE-2018-12426P2CRITICALCVSS 9.8fixed in 8.0.072018-07-02
CVE-2018-12426 [CRITICAL] CWE-434 CVE-2018-12426: The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Rem
The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation of allowed file types, as demonstrated by a v1/remote_upload request with a .php filename and the image/jpeg content type.
nvd
CVE-2019-11185P3CRITICALCVSS 9.8fixed in 8.0.262019-06-03
CVE-2019-11185 [CRITICAL] CVE-2019-11185: The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload v
The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete patch for CVE-2018-12426. Arbitrary file upload is achieved by using a non-blacklisted executable file extension in conjunction with a whitelisted file extension, and prepending "magic bytes" to the payload to p
nvd
CVE-2019-12498P3CRITICALCVSS 9.8fixed in 8.0.332020-03-20
CVE-2019-12498 [CRITICAL] CWE-862 CVE-2019-12498: The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without i
The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.
nvd
CVE-2018-9864P4MEDIUMCVSS 6.1fixed in 8.0.062018-04-09
CVE-2018-9864 [MEDIUM] CWE-79 CVE-2018-9864: The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.
The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.
nvd
CVE-2019-9913P4MEDIUMCVSS 6.1fixed in 8.0.182019-03-22
CVE-2019-9913 [MEDIUM] CWE-79 CVE-2019-9913: The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-m
The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.
nvd
CVE-2018-11105P4MEDIUMCVSS 6.1fixed in 8.0.082018-05-15
CVE-2018-11105 [MEDIUM] CWE-79 CVE-2018-11105: There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress
There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplc_name) and "email" (aka wplc_email) input fields to wp-json/wp_live_chat_support/v1/start_chat whenever a malicious attacker would initiate a new chat with an administrator. NOTE: this issue exists because of an incomplete fix fo
nvd
CVE-2018-18460P4MEDIUMCVSS 6.1v8.0.152018-10-18
CVE-2018-18460 [MEDIUM] CWE-79 CVE-2018-18460: XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term pa
XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admin/admin.php wplivechat-menu-gdpr-page request.
nvd
CVE-2016-10879P4MEDIUMCVSS 6.1fixed in 6.2.022019-08-12
CVE-2016-10879 [MEDIUM] CWE-79 CVE-2016-10879: The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS.
The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS.
nvd
CVE-2017-18507P4MEDIUMCVSS 6.1fixed in 7.1.052019-08-13
CVE-2017-18507 [MEDIUM] CWE-79 CVE-2017-18507: The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS.
The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS.
nvd
CVE-2017-2187P4MEDIUMCVSS 6.1≤ 7.0.062017-06-09
CVE-2017-2187 [MEDIUM] CWE-79 CVE-2017-2187: Cross-site scripting vulnerability in WP Live Chat Support prior to version 7.0.07 allows remote att
Cross-site scripting vulnerability in WP Live Chat Support prior to version 7.0.07 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2017-18508P4MEDIUMCVSS 6.1fixed in 7.1.032019-08-12
CVE-2017-18508 [MEDIUM] CWE-79 CVE-2017-18508: The wp-live-chat-support plugin before 7.1.03 for WordPress has XSS.
The wp-live-chat-support plugin before 7.1.03 for WordPress has XSS.
nvd
CVE-2014-10386P4MEDIUMCVSS 6.1fixed in 4.1.02019-08-22
CVE-2014-10386 [MEDIUM] CWE-74 CVE-2014-10386: The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.
The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.
nvd