plugin

Tidio Live Chat Vulnerabilities

2 known security issues reported for the Tidio Live Chat WordPress plugin. Most recent disclosed Sep 20, 2022.

1 high 1 medium

Running Tidio Live Chat on your site? Check whether your installed version is affected.

Scan your site free

Tidio – Live Chat, Chatbots & Email Integration <= 5.2.0 - Sensitive Information Disclosure

medium

The Tidio plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 5.2.0. This could allow unauthenticated attackers to extract system information such as installation paths on misconfigured servers with verbose error output enabled.

CVSS:
5.3
Affected:
up to 5.2.0
Fixed in:
5.3.0
Disclosed:
Sep 20, 2022

Tidio Live Chat < 4.2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

high

The Tidio Live Chat plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.0. This is due to missing or incorrect nonce validation on the toggleAsync(), ajaxSetProjectKeys(), and uninstall() functions. This makes it possible for unauthenticated attackers to inject arbitra...

CVSS:
8.8
Affected:
up to 4.2.1
Fixed in:
4.2.1
Disclosed:
Nov 5, 2019

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database