Extension WordPress
Vulnérabilités Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist
Cette page rassemble les failles publiées pour Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist
7 fiches
Bit Assist <= 1.5.11 – Missing Authorization
The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions…
*-1.5.11
1.6.0
19/12/2025
Bit Assist <= 1.5.4 – Unauthenticated Path Traversal
The Chat Widget: Customer Support Button with SMS Call Button, Click to Chat Messenger, Live Chat Support Chat Button – Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.4.…
*-1.5.4
1.5.5
28/03/2025
Bit Assist <= 1.5.2 – Path Traversal to Authenticated (Subscriber+) Arbitrary File Read via fileID Parameter
Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the fileID Parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents…
*-1.5.2
1.5.3
15/02/2025
Bit Assist <= 1.5.2 – Path Traversal to Authenticated (Administrator+) Arbitrary File Read via downloadResponseFile Function
Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents…
*-1.5.2
1.5.3
13/02/2025
Bit Assist <= 1.5.2 – Authenticated (Subscriber+) SQL Injection via id Parameter
Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
*-1.5.2
1.5.3
13/02/2025
Bit Assist <= 1.1.9 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Bit Assist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
[*, 1.2)
1.2
18/09/2023
Bit Assist <= 1.1.8 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Bit Assist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-1.1.8
1.1.9
27/07/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.