Vulnerabilities > 3CX > Live Chat > 8.0.15

DATE CVE VULNERABILITY TITLE RISK
2020-03-20 CVE-2019-12498 Missing Authorization vulnerability in 3CX Live Chat
The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.
network
low complexity
3cx CWE-862
7.5
2018-10-18 CVE-2018-18460 Cross-site Scripting vulnerability in 3CX Live Chat 8.0.15
XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admin/admin.php wplivechat-menu-gdpr-page request.
network
low complexity
3cx CWE-79
6.1