plugin

Wp Live Chat Support Vulnerabilities

44 known security issues reported for the Wp Live Chat Support WordPress plugin. Most recent disclosed Apr 28, 2022.

2 critical 1 high 12 medium

Running Wp Live Chat Support on your site? Check whether your installed version is affected.

Scan your site free

3CX Live Chat <= 9.4.2 - Local File Inclusion

high

The 3CX Live Chat plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 9.4.2 via the evaluate_php_template() function. This allows authenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used...

CVSS:
8.8
Affected:
up to 9.4.2
Fixed in:
9.4.3
Disclosed:
Apr 28, 2022

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 9.4.3

unknown

The 3CX Live Chat plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 9.4.2 via the evaluate_php_template() function. This allows authenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used...

Affected:
up to 9.4.3
Fixed in:
9.4.3
Disclosed:
Apr 28, 2022

WP Live Chat Support <= 8.1.9 - Stored Cross-Site Scripting

medium

The WP Live Chat Support for WordPress is vulnerable to Stored Cross-Site Scripting via the quick response and post functions in versions up to, and including, 8.1.9 due to insufficient input sanitization and output escaping. This makes it possible for subscriber-level attackers to inject arbitrary web scripts in pages...

CVSS:
5.4
Affected:
up to 8.1.9
Fixed in:
8.2.0
Disclosed:
Jul 12, 2020

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.2.0

unknown

The WP Live Chat Support for WordPress is vulnerable to Stored Cross-Site Scripting via the quick response and post functions in versions up to, and including, 8.1.9 due to insufficient input sanitization and output escaping. This makes it possible for subscriber-level attackers to inject arbitrary web scripts in pages...

Affected:
up to 8.2.0
Fixed in:
8.2.0
Disclosed:
Jul 12, 2020

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.2.0

unknown

Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by Chevon Phillip in WordPress 3CX Live Chat plugin (versions <= 8.1.9).

Affected:
up to 8.2.0
Fixed in:
8.2.0
Disclosed:
Jul 12, 2020

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.33

unknown

[en] The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.

Affected:
up to 8.0.33
Fixed in:
8.0.33
Disclosed:
Mar 20, 2020

CVE-2019-12498 on NVD →

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 4.1.0

unknown

[en] The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.

Affected:
up to 4.1.0
Fixed in:
4.1.0
Disclosed:
Aug 22, 2019

CVE-2014-10386 on NVD →

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 7.1.05

unknown

[en] The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS.

Affected:
up to 7.1.05
Fixed in:
7.1.05
Disclosed:
Aug 13, 2019

CVE-2017-18507 on NVD →

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.27

unknown

[en] The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.

Affected:
up to 8.0.27
Fixed in:
8.0.27
Disclosed:
Aug 12, 2019

CVE-2019-14950 on NVD →

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 6.2.04

unknown

[en] The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS.

Affected:
up to 6.2.04
Fixed in:
6.2.04
Disclosed:
Aug 12, 2019

CVE-2016-10879 on NVD →

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 1.7.03

unknown

[en] The wp-live-chat-support plugin before 7.1.03 for WordPress has XSS.

Affected:
up to 1.7.03
Fixed in:
1.7.03
Disclosed:
Aug 12, 2019

CVE-2017-18508 on NVD →

WP Live Chat Support <= 8.0.32 - Unprotected Functions

critical

The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.

CVSS:
9.8
Affected:
up to 8.0.33
Fixed in:
8.0.33
Disclosed:
May 31, 2019

CVE-2019-12498 on NVD →

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.27

unknown

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability found by John Castro (Sucuri) in WordPress WP Live Chat Support plugin (versions <= 8.0.26).

Affected:
up to 8.0.27
Fixed in:
8.0.27
Disclosed:
May 21, 2019

WP Live Chat Support <= 8.0.27 - Unauthenticated Stored Cross-Site Scripting

medium

The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.

CVSS:
6.1
Affected:
up to 8.0.26
Fixed in:
8.0.27
Disclosed:
May 15, 2019

CVE-2019-14950 on NVD →

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.18

unknown

[en] The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.

Affected:
up to 8.0.18
Fixed in:
8.0.18
Disclosed:
Mar 21, 2019

CVE-2019-9913 on NVD →

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.18

unknown

Reflected Cross-Site Scripting (XSS) vulnerability found by Tim Coen in WordPress WP Live Chat Support plugin (versions <= 8.0.17).

Affected:
up to 8.0.18
Fixed in:
8.0.18
Disclosed:
Mar 12, 2019

WP Live Chat Support <= 8.0.17 - Cross-Site Scripting

medium

The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.

CVSS:
6.1
Affected:
up to 8.0.18
Fixed in:
8.0.18
Disclosed:
Feb 5, 2019

CVE-2019-9913 on NVD →

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.18

unknown

[en] XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admin/admin.php wplivechat-menu-gdpr-page request.

Affected:
up to 8.0.18
Fixed in:
8.0.18
Disclosed:
Oct 18, 2018

CVE-2018-18460 on NVD →

WP Live Chat Support <= 8.0.15 - Cross-Site Scripting

medium

XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admin/admin.php wplivechat-menu-gdpr-page request.

CVSS:
6.1
Affected:
up to 8.0.15
Fixed in:
8.0.16
Disclosed:
Oct 17, 2018

CVE-2018-18460 on NVD →

3CX Live Chat <= 8.0.07 - Cross-Site Scripting

medium

There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplc_name) and "email" (aka wplc_email) input fields to wp-json/wp_live_chat_support/v1/start_chat whenever a malicious attacker would initiate a new chat with an administrator. NOTE: this issue exist...

CVSS:
6.1
Affected:
up to 8.0.07
Fixed in:
8.0.08
Disclosed:
Jul 2, 2018

CVE-2018-11105 on NVD →

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.08

unknown

Authenticated Cross-Site Scripting (XSS) vulnerability found by Riccardo ten Cate in WordPress WP Live Chat Support plugin (versions <=8.0.07).

Affected:
up to 8.0.08
Fixed in:
8.0.08
Disclosed:
May 17, 2018

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.08

unknown

[en] There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplc_name) and "email" (aka wplc_email) input fields to wp-json/wp_live_chat_support/v1/start_chat whenever a malicious attacker would initiate a new chat with an administrator. NOTE: this issue...

Affected:
up to 8.0.08
Fixed in:
8.0.08
Disclosed:
May 15, 2018

CVE-2018-11105 on NVD →

WP Live Chat Support <= 8.0.05 - Stored Cross-Site Scripting

medium

The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.

CVSS:
6.1
Affected:
up to 8.0.05
Fixed in:
8.0.06
Disclosed:
Apr 9, 2018

CVE-2018-9864 on NVD →

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.06

unknown

Unauthenticated Stored XSS vulnerability found by Luigi in WordPress WP Live Chat Support plugin (versions <=8.0.05).

Affected:
up to 8.0.06
Fixed in:
8.0.06
Disclosed:
Apr 9, 2018

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.06

unknown

[en] The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.

Affected:
up to 8.0.06
Fixed in:
8.0.06
Disclosed:
Apr 9, 2018

CVE-2018-9864 on NVD →

WP Live Chat Support <= 7.1.04 - Cross-Site Scripting

medium

The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS.

CVSS:
6.1
Affected:
up to 7.1.04
Fixed in:
7.1.05
Disclosed:
Aug 2, 2017

CVE-2017-18507 on NVD →

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 7.1.05

unknown

Cross-Site Scripting (XSS) vulnerability discovered by Omaid Faizyar in WordPress WP Live Chat Support plugin version 7.1.0.4 and earlier versions. The vulnerability allows an attacker to send Cross-Site Scripting (XSS) payloads by chat. Update the WordPress WP Live Chat Support plugin to the latest available version (...

Affected:
up to 7.1.05
Fixed in:
7.1.05
Disclosed:
Jul 30, 2017

WP Live Chat Support <= 7.1.02 - Cross-Site Scripting

medium

The wp-live-chat-support plugin before 7.1.03 for WordPress has XSS.

CVSS:
6.1
Affected:
up to 7.1.02
Fixed in:
7.1.03
Disclosed:
Jul 10, 2017

CVE-2017-18508 on NVD →

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 7.0.07

unknown

[en] Cross-site scripting vulnerability in WP Live Chat Support prior to version 7.0.07 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected:
up to 7.0.07
Fixed in:
7.0.07
Disclosed:
Jun 9, 2017

CVE-2017-2187 on NVD →

WP Live Chat Support <= 7.0.06 - Cross-Site Scripting

medium

Cross-site scripting vulnerability in WP Live Chat Support prior to version 7.0.07 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
6.1
Affected:
up to 7.0.06
Fixed in:
7.0.07
Disclosed:
May 16, 2017

CVE-2017-2187 on NVD →

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 6.2.04

unknown

WP Live Chat Support Plugin 6.2.03 is prone to a Cross-site scripting (XSS) vulnerability. This vulnerability allows to perform a number of arbitrary actions via wp-live-chat-support/functions.php (line 1233). Update the plugin. This vulnerability was fixed in 6.2.04.

Affected:
up to 6.2.04
Fixed in:
6.2.04
Disclosed:
Sep 11, 2016

3CX Free Live Chat <= 6.2.03 - Unauthenticated Stored Cross-Site Scripting

medium

The WP Live Chat Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in versions up to, and including, 6.2.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will...

CVSS:
6.1
Affected:
up to 6.2.03
Fixed in:
6.2.04
Disclosed:
Aug 1, 2016

CVE-2016-10879 on NVD →

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 6.2.04

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Affected:
up to 6.2.04
Fixed in:
6.2.04
Disclosed:
Aug 1, 2016

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 6.2.02

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Affected:
up to 6.2.02
Fixed in:
6.2.02
Disclosed:
Jul 11, 2016

WP Live Chat Support <= 4.3.5 - Blind SQL Injection

critical

The WP Live Chat Support plugin for WordPress is vulnerable to blind SQL Injection via the 'cid' and 'status' parameter in versions up to, and including, 4.3.5 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenti...

CVSS:
9.8
Affected:
up to 4.3.5
Fixed in:
4.4.0
Disclosed:
Jul 6, 2015

WP Live Chat Support <= 4.3.5 - Stored Cross-site Scripting

medium

The WP Live Chat Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wplc_update_admin_chat_table’ parameter in versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber level permiss...

CVSS:
6.4
Affected:
up to 4.3.5
Fixed in:
4.4.0
Disclosed:
Jul 6, 2015

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 4.4.0

unknown

Because of this vulnerability, unauthenticated remote attackers can execute arbitrary SQL commands. Update the plugin.

Affected:
up to 4.4.0
Fixed in:
4.4.0
Disclosed:
Jul 6, 2015

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 4.4.0

unknown

The WP Live Chat Support plugin for WordPress is vulnerable to blind SQL Injection via the 'cid' and 'status' parameter in versions up to, and including, 4.3.5 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenti...

Affected:
up to 4.4.0
Fixed in:
4.4.0
Disclosed:
Jul 6, 2015

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 4.4.0

unknown

The WP Live Chat Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wplc_update_admin_chat_table’ parameter in versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber level permiss...

Affected:
up to 4.4.0
Fixed in:
4.4.0
Disclosed:
Jul 6, 2015

WP Live Chat Support < 4.1.0 - JavaScript Code Injection

medium

The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.

CVSS:
6.1
Affected:
up to 4.1.0
Fixed in:
4.1.0
Disclosed:
Jul 20, 2014

CVE-2014-10386 on NVD →

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.2.0

unknown

There is a Stored Cross-Site Scripting (XSS) in WP-Live Chat by 3CX v. 8.1.9 By 3CX within the Quick Response function. Due to the nature of this vulnerability, a malicious attack with access to a WordPress multisite and permissions to this plugin can craft a malformed JavaScript payload.

Affected:
up to 8.2.0
Fixed in:
8.2.0

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.08

unknown

The 3CX Live Chat WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 8.0.08
Fixed in:
8.0.08

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 6.2.04

unknown

The 3CX Live Chat WordPress plugin was affected by a Stored Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 6.2.04
Fixed in:
6.2.04

3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 4.4.0

unknown

The 3CX Live Chat WordPress plugin was affected by an Unauthenticated Blind SQL Injection security vulnerability.

Affected:
up to 4.4.0
Fixed in:
4.4.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database