Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
3cx live chat vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2019-11185
The WP Live Chat Support Pro plugin up to and including 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete patch for CVE-2018-12426. Arbitrary file upload is achieved by using a non-blacklisted executable file extension in conjun...
3cx Live Chat
383
VMScore
CVE-2016-10879
The wp-live-chat-support plugin prior to 6.2.02 for WordPress has XSS.
3cx Live Chat
383
VMScore
CVE-2019-14950
The wp-live-chat-support plugin prior to 8.0.27 for WordPress has XSS via the GDPR page.
3cx Live Chat
383
VMScore
CVE-2014-10386
The wp-live-chat-support plugin prior to 4.1.0 for WordPress has JavaScript injections.
3cx Live Chat
668
VMScore
CVE-2018-12426
The WP Live Chat Support Pro plugin prior to 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation of allowed file types, as demonstrated by a v1/remote_upload request with a .php filename and the image/jpeg content type.
3cx Live Chat
668
VMScore
CVE-2019-12498
The WP Live Chat Support plugin prior to 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.
3cx Live Chat
383
VMScore
CVE-2018-11105
There is stored cross site scripting in the wp-live-chat-support plugin prior to 8.0.08 for WordPress via the "name" (aka wplc_name) and "email" (aka wplc_email) input fields to wp-json/wp_live_chat_support/v1/start_chat whenever a malicious attacker would ini...
3cx Live Chat
383
VMScore
CVE-2017-18507
The wp-live-chat-support plugin prior to 7.1.05 for WordPress has XSS.
3cx Live Chat
383
VMScore
CVE-2017-18508
The wp-live-chat-support plugin prior to 7.1.03 for WordPress has XSS.
3cx Live Chat
383
VMScore
CVE-2017-2187
Cross-site scripting vulnerability in WP Live Chat Support prior to version 7.0.07 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
3cx Live Chat
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3380
CVE-2024-1694
local file inclusion
CVE-2024-5645
CVE-2024-24919
XSS
CVE-2024-36774
CVE-2024-21306
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »