plugin

Web Instant Messenger Vulnerabilities

4 known security issues reported for the Web Instant Messenger WordPress plugin. Most recent disclosed Oct 20, 2020.

1 high

Running Web Instant Messenger on your site? Check whether your installed version is affected.

Scan your site free

Web Instant Messenger [web-instant-messenger] <= 1.1.2 (unfixed + closed)

unknown

Unauthenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by m0ze (Ex.Mi) in WordPress Web Instant Messenger plugin (versions <= 1.1.2).

Affected:
up to 1.1.2
Fix:
No patched version reported
Disclosed:
Oct 20, 2020

Web Instant Messenger <= 1.1.2 and LocalWeb In One <= 1.6.4 - Stored Cross-Site Scripting

high

The Web Instant Messenger and LocalWeb In One plugins for WordPress are vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.4 (NOTE: Web Instant Messenger's latest version 1.1.2 is unpatched) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...

CVSS:
7.2
Affected:
up to 1.1.2
Fix:
No patched version reported
Disclosed:
Oct 12, 2020

Web Instant Messenger [web-instant-messenger] <= 1.1.2 (unfixed + closed)

unknown

The Web Instant Messenger and LocalWeb In One plugins for WordPress are vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.4 (NOTE: Web Instant Messenger's latest version 1.1.2 is unpatched) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...

Affected:
up to 1.1.2
Fix:
No patched version reported
Disclosed:
Oct 12, 2020

Web Instant Messenger [web-instant-messenger] <= 1.1.2 (unfixed + closed)

unknown

An Unauthenticated Stored XSS vulnerability was discovered in the LocalWeb All In One plugin v1.6.3 for WordPress. There is an older version of this plugin called Web Instant Messenger, latest version is v1.1.1. The specificity of this plugin is that it interacts with the remote host www.localweb.it, so the paylo...

Affected:
up to 1.1.2
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database