Vulnerabilities > 3CX > Live Chat > 4.1.2

DATE CVE VULNERABILITY TITLE RISK
2020-03-20 CVE-2019-12498 Missing Authorization vulnerability in 3CX Live Chat
The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.
network
low complexity
3cx CWE-862
critical
9.8
2019-08-13 CVE-2017-18507 Cross-site Scripting vulnerability in 3CX Live Chat
The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS.
network
low complexity
3cx CWE-79
6.1
2019-08-12 CVE-2019-14950 Cross-site Scripting vulnerability in 3CX Live Chat
The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.
network
low complexity
3cx CWE-79
6.1
2019-08-12 CVE-2017-18508 Cross-site Scripting vulnerability in 3CX Live Chat
The wp-live-chat-support plugin before 7.1.03 for WordPress has XSS.
network
low complexity
3cx CWE-79
6.1
2019-08-12 CVE-2016-10879 Cross-site Scripting vulnerability in 3CX Live Chat
The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS.
network
low complexity
3cx CWE-79
6.1
2019-06-03 CVE-2019-11185 Unrestricted Upload of File with Dangerous Type vulnerability in 3CX Live Chat
The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability.
network
low complexity
3cx CWE-434
critical
9.8
2019-03-22 CVE-2019-9913 Cross-site Scripting vulnerability in 3CX Live Chat
The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.
network
low complexity
3cx CWE-79
6.1
2018-07-02 CVE-2018-12426 Unrestricted Upload of File with Dangerous Type vulnerability in 3CX Live Chat
The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation of allowed file types, as demonstrated by a v1/remote_upload request with a .php filename and the image/jpeg content type.
network
low complexity
3cx CWE-434
critical
9.8
2018-05-15 CVE-2018-11105 Cross-site Scripting vulnerability in 3CX Live Chat
There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplc_name) and "email" (aka wplc_email) input fields to wp-json/wp_live_chat_support/v1/start_chat whenever a malicious attacker would initiate a new chat with an administrator.
network
low complexity
3cx CWE-79
6.1
2018-04-09 CVE-2018-9864 Cross-site Scripting vulnerability in 3CX Live Chat
The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.
network
low complexity
3cx CWE-79
6.1