plugin

Chat Help Vulnerabilities

6 known security issues reported for the Chat Help WordPress plugin. Most recent disclosed Jul 16, 2026.

1 high 3 medium

Running Chat Help on your site? Check whether your installed version is affected.

Scan your site free

ChatHelp <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes

medium

The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes in all versions up to, and including, 3.5.1 due to insufficient input sanitization and output escaping. This makes it possib...

CVSS:
6.4
Affected:
up to 3.5.1
Fixed in:
3.5.2
Disclosed:
Jul 16, 2026

CVE-2026-15759 on NVD →

Chat Help – Click to Chat Button &amp; Form [chat-help] <= 3.1.3 (unfixed)

unknown

[en] Missing Authorization vulnerability in ThemeAtelier Chat Help chat-help allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chat Help: from n/a through <= 3.1.3.

Affected:
up to 3.1.3
Fix:
No patched version reported
Disclosed:
Nov 21, 2025

CVE-2025-66099 on NVD →

Chat Help – Click to Chat Button & Form <= 3.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure

high

The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the REST API endpoints /wp-json/chat-help/v1/leads and /wp-json/chat-help/v1/leads/{id}. This is due to the plugin not performing any authentication and author...

CVSS:
7.5
Affected:
up to 3.1.3
Fixed in:
3.1.4
Disclosed:
Nov 18, 2025

CVE-2026-15291 on NVD →

Chat Help <= 3.1.3 - Missing Authorization

medium

The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.1.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.1.3
Fixed in:
3.1.4
Disclosed:
Nov 11, 2025

CVE-2025-66099 on NVD →

Appsero <= 2.0.0 - Missing Authorization via handle_optin_optout

medium

The Appsero analytics tool used in several plugins is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout function in versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to opt-in or opt-out of tracking. This was patched in...

CVSS:
4.3
Affected:
up to 1.4.9
Fixed in:
1.6.0
Disclosed:
Apr 11, 2024

CVE-2024-32110 on NVD →

Chat Help – Click to Chat Button &amp; Form [chat-help] < 1.6.0

unknown
Affected:
up to 1.6.0
Fixed in:
1.6.0

CVE-2024-32110 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database