Extension WordPress

Vulnérabilités Hive Support | AI-Powered Help Desk, Live Chat and Chatbot

Cette page rassemble les failles publiées pour Hive Support | AI-Powered Help Desk, Live Chat and Chatbot, leurs plages de versions affectées et les correctifs signalés dans la base locale.

11Vulnérabilités
0Critiques
11Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Hive Support | AI-Powered Help Desk, Live Chat and Chatbot

11 fiches

CVE-2025-5018 Élevée · 7,1
Hive Support | AI-Powered Help Desk, Live Chat and Chatbot

Hive Support <= 1.2.5 – Authenticated (Subscriber+) Missing Authorization via hs_update_ai_chat_settings and hive_lite_support_get_all_binbox

The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_update_ai_chat_settings() and hive_lite_support_get_all_binbox() functions in all versions up to, and including, 1.2.5. This makes it…

Versions affectées

*-1.2.5

Correctif

1.2.6

Publication

05/06/2025

CVE-2025-32666 Moyenne · 6,1
Hive Support | AI-Powered Help Desk, Live Chat and Chatbot

Hive Support <= 1.2.5 – Reflected Cross-Site Scripting

The Hive Support plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

Versions affectées

*-1.2.5

Correctif

1.2.6

Publication

15/04/2025

CVE-2025-32214 Moyenne · 6,4
Hive Support | AI-Powered Help Desk, Live Chat and Chatbot

Hive Support <= 1.2.11 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The Hive Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and…

Versions affectées

*-1.2.11

Correctif

1.2.12

Publication

08/04/2025

CVE-2024-54304 Moyenne · 6,5
Hive Support | AI-Powered Help Desk, Live Chat and Chatbot

Hive Support – WordPress Help Desk <= 1.1.2 – Authenticated (Subscriber+) SQL Injection

The Hive Support – WordPress Help Desk plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

Versions affectées

*-1.1.2

Correctif

1.1.3

Publication

11/12/2024

CVE-2024-52370 Élevée · 8,8
Hive Support | AI-Powered Help Desk, Live Chat and Chatbot

Hive Support – WordPress Help Desk <= 1.1.1 – Authenticated (Subscriber+) Arbitrary File Upload

The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including,…

Versions affectées

*-1.1.1

Correctif

1.1.2

Publication

11/11/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités