Extension WordPress
Vulnérabilités ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form
Cette page rassemble les failles publiées pour ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form
4 fiches
ChatHelp <= 3.5.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes
The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes in all versions up to, and including, 3.5.1…
*-3.5.1
3.5.2
16/07/2026
Chat Help – Click to Chat Button & Form <= 3.1.3 – Missing Authorization to Unauthenticated Sensitive Information Exposure
The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the REST API endpoints /wp-json/chat-help/v1/leads and /wp-json/chat-help/v1/leads/{id}. This is due…
*-3.1.3
3.1.4
18/11/2025
Chat Help <= 3.1.3 – Missing Authorization
The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.1.3. This makes it…
*-3.1.3
3.1.4
11/11/2025
Appsero <= 2.0.0 – Missing Authorization via handle_optin_optout
The Appsero analytics tool used in several plugins is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout function in versions up to, and including, 2.0.0. This makes it possible for unauthenticated…
*-1.4.9
1.6.0
11/04/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.