ChatHelp <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes
medium
The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes in all versions up to, and including, 3.5.1 due to insufficient input sanitization and output escaping. This makes it possib...
- CVSS:
- 6.4
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.2
- Disclosed:
- Jul 16, 2026
CVE-2026-15759 on NVD →
Chat Help – Click to Chat Button & Form [chat-help] <= 3.1.3 (unfixed)
unknown
[en] Missing Authorization vulnerability in ThemeAtelier Chat Help chat-help allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chat Help: from n/a through <= 3.1.3.
- Affected:
- up to 3.1.3
- Fix:
- No patched version reported
- Disclosed:
- Nov 21, 2025
CVE-2025-66099 on NVD →
Chat Help – Click to Chat Button & Form <= 3.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure
high
The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the REST API endpoints /wp-json/chat-help/v1/leads and /wp-json/chat-help/v1/leads/{id}. This is due to the plugin not performing any authentication and author...
- CVSS:
- 7.5
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.4
- Disclosed:
- Nov 18, 2025
CVE-2026-15291 on NVD →
Chat Help <= 3.1.3 - Missing Authorization
medium
The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.1.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.4
- Disclosed:
- Nov 11, 2025
CVE-2025-66099 on NVD →
Appsero <= 2.0.0 - Missing Authorization via handle_optin_optout
medium
The Appsero analytics tool used in several plugins is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout function in versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to opt-in or opt-out of tracking. This was patched in...
- CVSS:
- 4.3
- Affected:
- up to 1.4.9
- Fixed in:
- 1.6.0
- Disclosed:
- Apr 11, 2024
CVE-2024-32110 on NVD →
Chat Help – Click to Chat Button & Form [chat-help] < 1.6.0
unknown
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.0
CVE-2024-32110 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database