Extension WordPress
Vulnérabilités 3CX Free Live Chat, Calls & Messaging
Cette page rassemble les failles publiées pour 3CX Free Live Chat, Calls & Messaging, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de 3CX Free Live Chat, Calls & Messaging
15 fiches
3CX Live Chat <= 9.4.2 – Local File Inclusion
The 3CX Live Chat plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 9.4.2 via the evaluate_php_template() function. This allows authenticated attackers to include and execute arbitrary files on the server, allowing…
*-9.4.2
9.4.3
28/04/2022
WP Live Chat Support <= 8.1.9 – Stored Cross-Site Scripting
The WP Live Chat Support for WordPress is vulnerable to Stored Cross-Site Scripting via the quick response and post functions in versions up to, and including, 8.1.9 due to insufficient input sanitization and output escaping. This makes it…
*-8.1.9
8.2.0
12/07/2020
WP Live Chat Support <= 8.0.32 – Unprotected Functions
The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.
[*, 8.0.33)
8.0.33
31/05/2019
WP Live Chat Support <= 8.0.27 – Unauthenticated Stored Cross-Site Scripting
The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.
*-8.0.26
8.0.27
15/05/2019
WP Live Chat Support <= 8.0.17 – Cross-Site Scripting
The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.
[*, 8.0.18)
8.0.18
05/02/2019
WP Live Chat Support <= 8.0.15 – Cross-Site Scripting
XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admin/admin.php wplivechat-menu-gdpr-page request.
*-8.0.15
8.0.16
17/10/2018
3CX Live Chat <= 8.0.07 – Cross-Site Scripting
There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplc_name) and "email" (aka wplc_email) input fields to wp-json/wp_live_chat_support/v1/start_chat whenever a malicious attacker would initiate a new chat with an…
*-8.0.07
8.0.08
02/07/2018
WP Live Chat Support <= 8.0.05 – Stored Cross-Site Scripting
The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.
*-8.0.05
8.0.06
09/04/2018
WP Live Chat Support <= 7.1.04 – Cross-Site Scripting
The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS.
*-7.1.04
7.1.05
02/08/2017
WP Live Chat Support <= 7.1.02 – Cross-Site Scripting
The wp-live-chat-support plugin before 7.1.03 for WordPress has XSS.
*-7.1.02
7.1.03
10/07/2017
WP Live Chat Support <= 7.0.06 – Cross-Site Scripting
Cross-site scripting vulnerability in WP Live Chat Support prior to version 7.0.07 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
*-7.0.06
7.0.07
16/05/2017
3CX Free Live Chat <= 6.2.03 – Unauthenticated Stored Cross-Site Scripting
The WP Live Chat Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in versions up to, and including, 6.2.03 due to insufficient input sanitization and output escaping. This makes it possible for…
*-6.2.03
6.2.04
01/08/2016
WP Live Chat Support <= 4.3.5 – Stored Cross-site Scripting
The WP Live Chat Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wplc_update_admin_chat_table’ parameter in versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. This makes it possible for…
*-4.3.5
4.4.0
06/07/2015
WP Live Chat Support <= 4.3.5 – Blind SQL Injection
The WP Live Chat Support plugin for WordPress is vulnerable to blind SQL Injection via the 'cid' and 'status' parameter in versions up to, and including, 4.3.5 due to insufficient escaping on the user-supplied parameter and lack of…
*-4.3.5
4.4.0
06/07/2015
WP Live Chat Support < 4.1.0 – JavaScript Code Injection
The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.
[*, 4.1.0)
4.1.0
20/07/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.