Watcheezy Live chat plugin for WordPress <= 2.0 - Stored Cross-Site Scripting
mediumThe Target First WordPress Plugin v2.0, also previously known as Watcheezy, suffers from a critical unauthenticated stored XSS vulnerability. An attacker could change the licence key value through a POST on any URL with the 'weeWzKey' parameter that will be save as the 'weeID' option and is not sanitized.
- CVSS:
- 6.1
- Affected:
- up to 2.0
- Fixed in:
- 3.0
- Disclosed:
- May 5, 2021