{"error":0,"message":null,"data":{"name":"3CX Free Live Chat, Calls &amp; Messaging","plugin":"wp-live-chat-support","link":"https:\/\/wordpress.org\/plugins\/wp-live-chat-support\/","latest":"1782733680","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"0b8171f1c776370574fffe72a827f36f7ce1e4bf29e079e48c8b7f19ac178043","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.33","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.0.33","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-12498","name":"CVE-2019-12498","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-12498","description":"[en] The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.","date":"2020-03-20"},{"id":"f56f01774f7b828e51277df595b3339548e73839","name":"WP Live Chat Support <= 8.0.32 - Unprotected Functions","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-live-chat-support\/wp-live-chat-support-8032-unprotected-functions","description":"The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.","date":"2019-05-31"},{"id":"447c8090-d37e-406d-826c-4e1322beb727","name":"WP Live Chat Support &lt; 8.0.33 - Missing Permission Checks on some REST API Calls","link":"https:\/\/wpscan.com\/vulnerability\/447c8090-d37e-406d-826c-4e1322beb727","description":"The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}]}},{"uuid":"719d00e95ab6d9178e4e23b237f11b780a714e8886f6963c1d4ab089b0098406","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 4.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-10386","name":"CVE-2014-10386","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-10386","description":"[en] The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.","date":"2019-08-22"},{"id":"dc2a1524da9215a2bd04813289c5eac890378c31","name":"WP Live Chat Support < 4.1.0 - JavaScript Code Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-live-chat-support\/wp-live-chat-support-410-javascript-code-injection","description":"The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.","date":"2014-07-20"},{"id":"ae5d5fe1-ac99-40dc-bbed-923a902c6a07","name":"WP Live Chat Support &lt; 4.1.0 - XSS","link":"https:\/\/wpscan.com\/vulnerability\/ae5d5fe1-ac99-40dc-bbed-923a902c6a07","description":"The 3CX Live Chat WordPress plugin was affected by a XSS security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-74","name":"Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')","description":"The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component."}]}},{"uuid":"9771f4b8683c82c75fc6bc259c1f774b881cc0efb01d70c4cdf315ccc80b78a5","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 7.1.05","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.1.05","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2017-18507","name":"CVE-2017-18507","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2017-18507","description":"[en] The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS.","date":"2019-08-13"},{"id":"55c9b2f272ce5d28e93d36ad3e261bd477f0a907","name":"WP Live Chat Support <= 7.1.04 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-live-chat-support\/wp-live-chat-support-7104-cross-site-scripting","description":"The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS.","date":"2017-08-02"},{"id":"23043a51-ccf7-499c-90f9-44cee5812938","name":"WP Live Chat Support &lt; 7.1.05 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/23043a51-ccf7-499c-90f9-44cee5812938","description":"WP Live Chat Support is vulnerable by sending XSS payloads through chat.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"edf5848ba60c5798ab89e917a3beeb880445e9842c34b9440132f20cec8c3d35","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 1.7.03","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.7.03","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2017-18508","name":"CVE-2017-18508","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2017-18508","description":"[en] The wp-live-chat-support plugin before 7.1.03 for WordPress has XSS.","date":"2019-08-12"},{"id":"a1f97f9244018865d7b345edfb55a3ec45585cf0","name":"WP Live Chat Support <= 7.1.02 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-live-chat-support\/wp-live-chat-support-7102-cross-site-scripting","description":"The wp-live-chat-support plugin before 7.1.03 for WordPress has XSS.","date":"2017-07-10"},{"id":"eaef7049-c487-47ce-986d-a05f052f0b9a","name":"WP Live Chat Support &lt; 7.1.03 - XSS","link":"https:\/\/wpscan.com\/vulnerability\/eaef7049-c487-47ce-986d-a05f052f0b9a","description":"The 3CX Live Chat WordPress plugin was affected by a XSS security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"dfcf0f88eb59e23001b88584836c8247e33f2f59f3bb6bf2263db89bfe4ead6f","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 6.2.04","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.04","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2016-10879","name":"CVE-2016-10879","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2016-10879","description":"[en] The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS.","date":"2019-08-12"},{"id":"a73aec00e8b635baffe99c7953dab98e7ab338c3","name":"3CX Free Live Chat <= 6.2.03 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-live-chat-support\/3cx-free-live-chat-6203-unauthenticated-stored-cross-site-scripting","description":"The WP Live Chat Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in versions up to, and including, 6.2.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2016-08-01"},{"id":"d6daabea-5e19-4c20-b13a-5d34f6f3a0eb","name":"WP Live Chat Support &lt; 6.2.02 - Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/d6daabea-5e19-4c20-b13a-5d34f6f3a0eb","description":"The 3CX Live Chat WordPress plugin was affected by a Stored Cross-Site Scripting security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"0b5e7c53c51bae083c79605ef52fa5a2365d4b1e8c87b8c13e1194c81b619c2b","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.27","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.0.27","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-14950","name":"CVE-2019-14950","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-14950","description":"[en] The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.","date":"2019-08-12"},{"id":"622d9befbaa2f59d632f7fcf2c5287248c4e1f99","name":"WP Live Chat Support <= 8.0.27 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-live-chat-support\/wp-live-chat-support-8027-unauthenticated-stored-cross-site-scripting","description":"The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.","date":"2019-05-15"},{"id":"bf214e77-1bc4-4ec2-8812-685cdcf98a77","name":"WP Live Chat Support &lt; 8.0.27 - Unauthenticated Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/bf214e77-1bc4-4ec2-8812-685cdcf98a77","description":"The 3CX Live Chat WordPress plugin was affected by an Unauthenticated Stored XSS security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"c68c5b7fa19ae762fcec6233997a1b7280d45face16fecd2f88b3e291f33cb20","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.18","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.0.18","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-9913","name":"CVE-2019-9913","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-9913","description":"[en] The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin\/admin.php?page=wplivechat-menu-gdpr-page term XSS.","date":"2019-03-21"},{"id":"e0a3187b14bc75efbb08d7162801ab9c50690111","name":"WordPress WP Live Chat Support plugin <= 8.0.17 - Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-live-chat-support\/vulnerability\/wordpress-wp-live-chat-support-plugin-8-0-17-cross-site-scripting-xss-vulnerability","description":"Cross-Site Scripting (XSS) vulnerability found by Tim Coen in WordPress WP Live Chat Support plugin (versions <= 8.0.17).","date":"2019-03-22"},{"id":"9ad44bfa000a4fad894d7a5dfdaae46eac0b9bd7","name":"WP Live Chat Support <= 8.0.17 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-live-chat-support\/wp-live-chat-support-8017-cross-site-scripting","description":"The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin\/admin.php?page=wplivechat-menu-gdpr-page term XSS.","date":"2019-02-05"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"8036701b07e020aa172e712cce22fd7820b47ee9acbe1cadb599f283988ba42a","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.18","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.0.18","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-18460","name":"CVE-2018-18460","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-18460","description":"[en] XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules\/gdpr.php term parameter in a wp-admin\/admin.php wplivechat-menu-gdpr-page request.","date":"2018-10-18"},{"id":"8d4cc29acb7108a5ee544e8c95ea0e3d1ed35c9a","name":"WP Live Chat Support <= 8.0.15 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-live-chat-support\/wp-live-chat-support-8015-cross-site-scripting","description":"XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules\/gdpr.php term parameter in a wp-admin\/admin.php wplivechat-menu-gdpr-page request.","date":"2018-10-17"},{"id":"f41711fd-9ab0-4caa-82a6-8ec9e908af5e","name":"WP Live Chat Support &lt; 8.0.18 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/f41711fd-9ab0-4caa-82a6-8ec9e908af5e","description":"The 3CX Live Chat WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"599b5f8cdbc51683f223d1d8a9d08dfc3bc4f1c2c10fcb5c05387c11d0cfd110","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.08","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.0.08","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-11105","name":"CVE-2018-11105","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-11105","description":"[en] There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the \"name\" (aka wplc_name) and \"email\" (aka wplc_email) input fields to wp-json\/wp_live_chat_support\/v1\/start_chat whenever a malicious attacker would initiate a new chat with an administrator. NOTE: this issue exists because of an incomplete fix for CVE-2018-9864.","date":"2018-05-15"},{"id":"4b4069218aacb708cb42de0f22b30ff62ba27387","name":"3CX Live Chat <= 8.0.07 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-live-chat-support\/3cx-live-chat-8007-cross-site-scripting","description":"There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the \"name\" (aka wplc_name) and \"email\" (aka wplc_email) input fields to wp-json\/wp_live_chat_support\/v1\/start_chat whenever a malicious attacker would initiate a new chat with an administrator. NOTE: this issue exists because of an incomplete fix for CVE-2018-9864.","date":"2018-07-02"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"15599e17b079854ccf4360520b87b7fb5ff04475d529147d259a1d4f4fde0603","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.06","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.0.06","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-9864","name":"CVE-2018-9864","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-9864","description":"[en] The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.","date":"2018-04-09"},{"id":"cd45f26e0cb17d436906876ce26dcdd4537df47c","name":"WP Live Chat Support <= 8.0.05 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-live-chat-support\/wp-live-chat-support-8005-stored-cross-site-scripting","description":"The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.","date":"2018-04-09"},{"id":"7d0b7476-7e11-434e-b1c7-85ea7a3b0f7e","name":"WP Live Chat Support &lt; 8.0.06 - Unauthenticated Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/7d0b7476-7e11-434e-b1c7-85ea7a3b0f7e","description":"An unauthenticated user can inject arbitrary javascript code in the admin panel by using the text field &quot;Name&quot; of WP Live Chat Support. The arbitrary code runs on the page wplivechat-menu-history.\r\n\r\nIn the file wp-live-chat-support.php there is no sanitization of $result-&gt;id (row 4439).\r\nWP Live Chat Support 8.0.05 is vulnerable, probably earlier versions too.\r\nThe vulnerability is fixed in WP Live Cjat Support 8.0.06","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"6044834f66f7150af5cb3a556e294f2122d545472b156212f327ec5b0b23ad2f","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 7.0.07","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.0.07","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2017-2187","name":"CVE-2017-2187","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2017-2187","description":"[en] Cross-site scripting vulnerability in WP Live Chat Support prior to version 7.0.07 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.","date":"2017-06-09"},{"id":"JVNDB-2017-000103","name":"WordPress plugin \"WP Live Chat Support\" vulnerable to cross-site scripting","link":"http:\/\/jvndb.jvn.jp\/jvndb\/JVNDB-2017-000103","description":"The WordPress plugin \"WP Live Chat Support\" provided by CODECABIN_ contains a cross-site scripting vulnerability (CWE-79).  Chris Liu reported this vulnerability to IPA. JPCERT\/CC coordinated with the developer under Information Security Early Warning Partnership.","date":"2017-06-01"},{"id":"b2c59c497696b8146a8603339647e92b1d57275b","name":"WP Live Chat Support <= 7.0.06 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-live-chat-support\/wp-live-chat-support-7006-cross-site-scripting","description":"Cross-site scripting vulnerability in WP Live Chat Support prior to version 7.0.07 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.","date":"2017-05-16"},{"id":"1074194e-3b81-4d7b-8745-c93cdba3afaa","name":"WP Live Chat Support &lt; 7.0.07 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/1074194e-3b81-4d7b-8745-c93cdba3afaa","description":"The 3CX Live Chat WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"6aeaa02b188df7fde63e93a04aa19bfb90fdad17e9e79c1bef996616984d0a95","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"fd0aab4fbf945ac4b73acb60dfaae3f7c29d40c0","name":"WordPress 3CX Live Chat plugin <= 8.1.9 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-live-chat-support\/vulnerability\/wordpress-3cx-live-chat-plugin-8-1-9-multiple-authenticated-stored-cross-site-scripting-xss-vulnerabilities","description":"Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by Chevon Phillip in WordPress 3CX Live Chat plugin (versions <= 8.1.9).","date":"2020-07-12"}],"impact":[]},{"uuid":"3c982547fea299f6c4721737601510c521ef4aa5ae470f82e51ff0fab363b719","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.27","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.0.27","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0cb5c9981ec9b606a6150fbf966053adc2056a09","name":"WordPress WP Live Chat Support plugin <= 8.0.26 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-live-chat-support\/vulnerability\/wordpress-wp-live-chat-support-plugin-8-0-26-unauthenticated-stored-cross-site-scripting-xss-vulnerability","description":"Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability found by John Castro (Sucuri) in WordPress WP Live Chat Support plugin (versions <= 8.0.26).","date":"2019-05-21"}],"impact":[]},{"uuid":"47d50f06afd5469b1b5a61825c7da66c82cce7582ebaf9158e3105d01a7410af","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.18","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.0.18","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ef71f6aa5beab3fe38cfa10d4229b12ac82f0a7f","name":"WordPress WP Live Chat Support plugin <= 8.0.17 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-live-chat-support\/vulnerability\/wordpress-wp-live-chat-support-plugin-8-0-17-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site Scripting (XSS) vulnerability found by Tim Coen in WordPress WP Live Chat Support plugin (versions <= 8.0.17).","date":"2019-03-12"}],"impact":[]},{"uuid":"327fd6e07b7c1c627bc2347344c7d91e1c58ee66b095d45b3ed21e6aa2254d8d","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.08","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.0.08","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"df9447b991aba69b72fc6f3e34db5c2357161184","name":"WordPress WP Live Chat Support plugin <=8.0.07 - Authenticated Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-live-chat-support\/vulnerability\/wordpress-wp-live-chat-support-plugin-8-0-07-authenticated-cross-site-scripting-xss-vulnerability","description":"Authenticated Cross-Site Scripting (XSS) vulnerability found by Riccardo ten Cate in WordPress WP Live Chat Support plugin (versions <=8.0.07).","date":"2018-05-17"}],"impact":[]},{"uuid":"755bac91c1c477a8515a6fdb66c47efc86ce0ba6e633a88e93a5163688e6a752","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.06","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.0.06","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f0ead7c7ed398a8e59a9c95a299593fafa49a4d1","name":"WordPress WP Live Chat Support plugin <=8.0.05 - Unauthenticated Stored XSS vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-live-chat-support\/vulnerability\/wordpress-wp-live-chat-support-plugin-8-0-05-unauthenticated-stored-xss-vulnerability","description":"Unauthenticated Stored XSS vulnerability found by Luigi in WordPress WP Live Chat Support plugin (versions <=8.0.05).","date":"2018-04-09"}],"impact":[]},{"uuid":"d69dc9946ce3f1b1a2f681a148671e2ba7973de357ecf681d95a2811dc533f82","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 7.1.05","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.1.05","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a24f03a224c3584c22106e53f4b60d182b47277b","name":"WordPress WP Live Chat Support plugin <=7.1.04 - Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-live-chat-support\/vulnerability\/wordpress-wp-live-chat-support-plugin-7-1-04-cross-site-scripting-xss-vulnerability","description":"Cross-Site Scripting (XSS) vulnerability discovered by Omaid Faizyar in WordPress WP Live Chat Support plugin version 7.1.0.4 and earlier versions. The vulnerability allows an attacker to send Cross-Site Scripting (XSS) payloads by chat.\nUpdate the WordPress WP Live Chat Support plugin to the latest available version (at least 7.1.05).","date":"2017-07-30"}],"impact":[]},{"uuid":"3a27417f028f6a76d10bb50c9060efcaf0ca67f9833ba3ac172101452e457a49","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 6.2.04","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.04","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e835dbdd1d4660ee062986b6ad5cd8d22ee53af0","name":"WordPress WP Live Chat Support Plugin 6.2.03 - XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-live-chat-support\/vulnerability\/wp-live-chat-support-plugin-6-2-03-xss","description":"WP Live Chat Support Plugin 6.2.03 is prone to a Cross-site scripting (XSS) vulnerability. This vulnerability allows to perform a number of arbitrary actions via wp-live-chat-support\/functions.php (line 1233).\nUpdate the plugin. This vulnerability was fixed in 6.2.04.","date":"2016-09-11"}],"impact":[]},{"uuid":"78424a2d0e1cb630a6a689d43a11338b2b1a4dd652c7f6b9fd6516add8b98d35","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 6.2.04","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.04","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4993ee1ea9256cf2732c41fc0a0399e941352a03","name":"WordPress Live Chat Support Plugin <= 6.2.03 - Stored Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-live-chat-support\/vulnerability\/wordpress-live-chat-support-plugin-6-2-03-stored-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary web script or HTML.\nUpdate the plugin.","date":"2016-08-01"}],"impact":[]},{"uuid":"889907454d97ff0b920034f494c3cf0f40b76701b3d86af70efbc1325b2816d0","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 6.2.02","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.02","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b659f2c4ac2d24f5d2f9b54081c19503f1c553bd","name":"WordPress Live Chat Support Plugin <= 6.2.01 - Stored Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-live-chat-support\/vulnerability\/wordpress-live-chat-support-plugin-6-2-01-stored-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary web script or HTML.\nUpdate the plugin.","date":"2016-07-11"}],"impact":[]},{"uuid":"c7145905f945871680620456c5b8c61666f10ac388292698ea12c10d3230592a","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 4.4.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.4.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"678ee171be7abb8c3544c114f4bfe42817b91f79","name":"WordPress Live Chat Support Plugin <= 4.3.5 - Unauthenticated Blind SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-live-chat-support\/vulnerability\/wordpress-live-chat-support-plugin-4-3-5-unauthenticated-blind-sql-injection","description":"Because of this vulnerability, unauthenticated remote attackers can execute arbitrary SQL commands.\nUpdate the plugin.","date":"2015-07-06"}],"impact":[]},{"uuid":"18e8cecdc80c6fdbcf32edeeed1b5029212edcd4a515386d172de413b36570b8","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 9.4.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.4.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4ff4268007f917d4703ae5fad88ae0154ca7b409","name":"3CX Live Chat <= 9.4.2 - Local File Inclusion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-live-chat-support\/3cx-live-chat-942-local-file-inclusion","description":"The 3CX Live Chat plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 9.4.2 via the evaluate_php_template() function. This allows authenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other \u201csafe\u201d file types can be uploaded and included.","date":"2022-04-28"}],"impact":[]},{"uuid":"f092b723d3df6c7a114f20cbb2d9d83ea9471dbf75beb29eb76bed1896351af5","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0591eadfac8bf007ec0280edff9834b939ba0bf3","name":"WP Live Chat Support <= 8.1.9 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-live-chat-support\/wp-live-chat-support-819-stored-cross-site-scripting","description":"The WP Live Chat Support for WordPress is vulnerable to Stored Cross-Site Scripting via the quick response and post functions in versions up to, and including, 8.1.9 due to insufficient input sanitization and output escaping. This makes it possible for subscriber-level attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2020-07-12"}],"impact":[]},{"uuid":"048e9cf61a24bff72a0ff857c5fb737353978479e6fc4728571c89b076e0d228","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 4.4.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.4.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3e8be9a7255492f081b220506e3958cad76fe6f8","name":"WP Live Chat Support <= 4.3.5 - Blind SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-live-chat-support\/wp-live-chat-support-435-blind-sql-injection","description":"The WP Live Chat Support plugin for WordPress is vulnerable to blind SQL Injection via the 'cid' and 'status' parameter in versions up to, and including, 4.3.5 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2015-07-06"}],"impact":[]},{"uuid":"05bee86732ac765e9c34e8917ce5ec0e365b5f4b43fe8b821e87d39398a63bf2","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 4.4.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.4.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0f8f873739cc0b4125833290b440e346499680f6","name":"WP Live Chat Support <= 4.3.5 - Stored Cross-site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-live-chat-support\/wp-live-chat-support-435-stored-cross-site-scripting","description":"The WP Live Chat Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018wplc_update_admin_chat_table\u2019 parameter in versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2015-07-06"}],"impact":[]},{"uuid":"3035c6612221a0aea3ce13f338644952230f667ea38aef5eee7632cf9ae0fc81","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"07b184e9-ce38-4aed-8b7c-fc1ac2e8f3dd","name":"WP-Live Chat by 3CX &lt; 8.2.0 - Authenticated Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/07b184e9-ce38-4aed-8b7c-fc1ac2e8f3dd","description":"There is a Stored Cross-Site Scripting (XSS) in WP-Live Chat by 3CX v. 8.1.9 By 3CX within the Quick Response function. Due to the nature of this vulnerability, a malicious attack with access to a WordPress multisite and permissions to this plugin can craft a malformed JavaScript payload.","date":null}],"impact":[]},{"uuid":"e6364b5ae0325d66bed3cb0da27d169b19d938e3801f4722b47435091912f80b","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 8.0.08","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.0.08","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0df5c464-833e-4042-a9ec-ceeb72d49185","name":"WP Live Chat Support &lt; 8.0.08 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/0df5c464-833e-4042-a9ec-ceeb72d49185","description":"The 3CX Live Chat WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"66f7567c4a66311e480a3d1951110aca4cb30f593a97cedf2eac06f73289bc8c","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 6.2.04","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.04","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5587dc18-d1f3-4c8b-820e-b9315165605f","name":"WP Live Chat Support &lt; 6.2.04 - Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/5587dc18-d1f3-4c8b-820e-b9315165605f","description":"The 3CX Live Chat WordPress plugin was affected by a Stored Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"d0facb01815d8c113681c672b5dada4777b02c07700b244c7eddc967801394ea","name":"3CX Free Live Chat, Calls &amp; Messaging [wp-live-chat-support] < 4.4.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.4.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6af4e134-0ceb-4876-b4fe-4a2d9c4b9e6d","name":"WP Live Chat Support &lt; 4.4.0 - Unauthenticated Blind SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/6af4e134-0ceb-4876-b4fe-4a2d9c4b9e6d","description":"The 3CX Live Chat WordPress plugin was affected by an Unauthenticated Blind SQL Injection security vulnerability.","date":null}],"impact":[]}]},"updated":"1776153795"}