Extension WordPress

Vulnérabilités Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist

Cette page rassemble les failles publiées pour Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist, leurs plages de versions affectées et les correctifs signalés dans la base locale.

7Vulnérabilités
0Critiques
7Avec correctif
6,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist

7 fiches

CVE-2025-68596 Moyenne · 5,3
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist

Bit Assist <= 1.5.11 – Missing Authorization

The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions…

Versions affectées

*-1.5.11

Correctif

1.6.0

Publication

19/12/2025

CVE-2025-30834 Moyenne · 5,8
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist

Bit Assist <= 1.5.4 – Unauthenticated Path Traversal

The Chat Widget: Customer Support Button with SMS Call Button, Click to Chat Messenger, Live Chat Support Chat Button – Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.4.…

Versions affectées

*-1.5.4

Correctif

1.5.5

Publication

28/03/2025

CVE-2025-0822 Moyenne · 6,5
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist

Bit Assist <= 1.5.2 – Path Traversal to Authenticated (Subscriber+) Arbitrary File Read via fileID Parameter

Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the fileID Parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents…

Versions affectées

*-1.5.2

Correctif

1.5.3

Publication

15/02/2025

CVE-2024-13791 Moyenne · 4,9
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist

Bit Assist <= 1.5.2 – Path Traversal to Authenticated (Administrator+) Arbitrary File Read via downloadResponseFile Function

Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents…

Versions affectées

*-1.5.2

Correctif

1.5.3

Publication

13/02/2025

CVE-2025-0821 Moyenne · 6,5
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist

Bit Assist <= 1.5.2 – Authenticated (Subscriber+) SQL Injection via id Parameter

Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…

Versions affectées

*-1.5.2

Correctif

1.5.3

Publication

13/02/2025

CVE-2023-51371 Moyenne · 4,4
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist

Bit Assist <= 1.1.9 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Bit Assist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

[*, 1.2)

Correctif

1.2

Publication

18/09/2023

CVE-2023-3667 Moyenne · 4,4
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist

Bit Assist <= 1.1.8 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Bit Assist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-1.1.8

Correctif

1.1.9

Publication

27/07/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités