Vulnerabilities > 3CX > Live Chat > 8.0.07
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-03-20 | CVE-2019-12498 | Missing Authorization vulnerability in 3CX Live Chat The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism. | 9.8 |
2019-08-12 | CVE-2019-14950 | Cross-site Scripting vulnerability in 3CX Live Chat The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page. | 6.1 |
2019-06-03 | CVE-2019-11185 | Unrestricted Upload of File with Dangerous Type vulnerability in 3CX Live Chat The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. | 9.8 |
2019-03-22 | CVE-2019-9913 | Cross-site Scripting vulnerability in 3CX Live Chat The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS. | 6.1 |
2018-05-15 | CVE-2018-11105 | Cross-site Scripting vulnerability in 3CX Live Chat There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplc_name) and "email" (aka wplc_email) input fields to wp-json/wp_live_chat_support/v1/start_chat whenever a malicious attacker would initiate a new chat with an administrator. | 6.1 |