SEGURIDAD DE PLUGINS

¿Es seguro 3CX Live Chat?

Chat with your website visitors in real-time for free! Engage with your customers and increase sales.

Qué hace este plugin

  • Slug: wp-live-chat-support
  • Autor: WP-LiveChat
  • 100000+ instalaciones activas
  • 92/100 calificación (821 reseñas en wordpress.org)
  • 4054579 descargas totales
  • En WordPress.org desde 2013-01-06

free live chatlive chatlive helplive supportwordpress live chat

Estado de mantenimiento

  • Última actualización: 2026-06-29 11:48am GMT
  • Probado hasta WordPress: 7.0.0
  • Requiere PHP: 5.4+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

12 CVEs conocidos registrados para 3CX Live Chat. Reportadas entre 2014 y 2022.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 9.4.3 Desconocido < 9.4.3 9.4.3 2022-04-28
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.2.0 Desconocido < 8.2.0 8.2.0 2020-07-12
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.2.0 Desconocido < 8.2.0 8.2.0 2020-07-12
CVE-2019-12498 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.33 Falta de control de autorización Crítica 9,8 < 8.0.33 8.0.33 2019-05-31
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.27 Desconocido < 8.0.27 8.0.27 2019-05-21
CVE-2019-14950 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.27 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 8.0.27 8.0.27 2019-05-15
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.18 Desconocido < 8.0.18 8.0.18 2019-03-12
CVE-2019-9913, CVE-2018-18460 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.18 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 8.0.18 8.0.18 2019-02-05

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 9.4.3

The 3CX Live Chat plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 9.4.2 via the evaluate_php_template() function. This allows authenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.2.0

Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by Chevon Phillip in WordPress 3CX Live Chat plugin (versions <= 8.1.9).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.2.0

The WP Live Chat Support for WordPress is vulnerable to Stored Cross-Site Scripting via the quick response and post functions in versions up to, and including, 8.1.9 due to insufficient input sanitization and output escaping. This makes it possible for subscriber-level attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2019-12498

The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.27

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability found by John Castro (Sucuri) in WordPress WP Live Chat Support plugin (versions <= 8.0.26).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2019-14950

The 3CX Live Chat WordPress plugin was affected by an Unauthenticated Stored XSS security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.18

Reflected Cross-Site Scripting (XSS) vulnerability found by Tim Coen in WordPress WP Live Chat Support plugin (versions <= 8.0.17).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2019-9913, CVE-2018-18460

The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

+ 25 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2018-18460 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.18 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 8.0.18 8.0.18 2018-10-17
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.08 Desconocido < 8.0.08 8.0.08 2018-05-17
CVE-2018-11105 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.08 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 8.0.08 8.0.08 2018-05-15
CVE-2018-9864 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.06 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 8.0.06 8.0.06 2018-04-09
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.06 Desconocido < 8.0.06 8.0.06 2018-04-09
CVE-2017-18507 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 7.1.05 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 7.1.05 7.1.05 2017-08-02
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 7.1.05 Desconocido < 7.1.05 7.1.05 2017-07-30
CVE-2017-18508 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 1.7.03 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 1.7.03 1.7.03 2017-07-10
CVE-2017-2187 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 7.0.07 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 7.0.07 7.0.07 2017-05-16
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04 Desconocido < 6.2.04 6.2.04 2016-09-11
CVE-2016-10879 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 6.2.04 6.2.04 2016-08-01
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04 Desconocido < 6.2.04 6.2.04 2016-08-01
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.02 Desconocido < 6.2.02 6.2.02 2016-07-11
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0 Desconocido < 4.4.0 4.4.0 2015-07-06
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0 Desconocido < 4.4.0 4.4.0 2015-07-06
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0 Desconocido < 4.4.0 4.4.0 2015-07-06
CVE-2014-10386 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.1.0 Neutralización incorrecta de elementos especiales en la salida usada por un componente posterior (inyección) Media 6,1 < 4.1.0 4.1.0 2014-07-20
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.2.0 Desconocido < 8.2.0 8.2.0
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.08 Desconocido < 8.0.08 8.0.08
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04 Desconocido < 6.2.04 6.2.04
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0 Desconocido < 4.4.0 4.4.0
WP Live Chat Support < 4.4.0 - Unauthenticated Blind SQL Injection Desconocido < 4.4.0 4.4.0
WP Live Chat Support < 6.2.04 - Stored Cross-Site Scripting (XSS) Desconocido < 6.2.04 6.2.04
CVE-2018-10234 WP Live Chat Support < 8.0.08 - Cross-Site Scripting (XSS) Desconocido < 8.0.08 8.0.08
WP-Live Chat by 3CX < 8.2.0 - Authenticated Stored Cross-Site Scripting Desconocido < 8.2.0 8.2.0

CVE-2018-18460

XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admin/admin.php wplivechat-menu-gdpr-page request.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.08

Authenticated Cross-Site Scripting (XSS) vulnerability found by Riccardo ten Cate in WordPress WP Live Chat Support plugin (versions <=8.0.07).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2018-11105

There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplc_name) and "email" (aka wplc_email) input fields to wp-json/wp_live_chat_support/v1/start_chat whenever a malicious attacker would initiate a new chat with an administrator. NOTE: this issue exists because of an incomplete fix for CVE-2018-9864.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2018-9864

An unauthenticated user can inject arbitrary javascript code in the admin panel by using the text field "Name" of WP Live Chat Support. The arbitrary code runs on the page wplivechat-menu-history. In the file wp-live-chat-support.php there is no sanitization of $result->id (row 4439). WP Live Chat Support 8.0.05 is vulnerable, probably earlier versions too. The vulnerability is fixed in WP Live Cjat Support 8.0.06

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.06

Unauthenticated Stored XSS vulnerability found by Luigi in WordPress WP Live Chat Support plugin (versions <=8.0.05).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2017-18507

WP Live Chat Support is vulnerable by sending XSS payloads through chat.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 7.1.05

Cross-Site Scripting (XSS) vulnerability discovered by Omaid Faizyar in WordPress WP Live Chat Support plugin version 7.1.0.4 and earlier versions. The vulnerability allows an attacker to send Cross-Site Scripting (XSS) payloads by chat. Update the WordPress WP Live Chat Support plugin to the latest available version (at least 7.1.05).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2017-18508

The 3CX Live Chat WordPress plugin was affected by a XSS security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

CVE-2017-2187

The WordPress plugin "WP Live Chat Support" provided by CODECABIN_ contains a cross-site scripting vulnerability (CWE-79). Chris Liu reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: jvndb.jvn.jp

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04

WP Live Chat Support Plugin 6.2.03 is prone to a Cross-site scripting (XSS) vulnerability. This vulnerability allows to perform a number of arbitrary actions via wp-live-chat-support/functions.php (line 1233). Update the plugin. This vulnerability was fixed in 6.2.04.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2016-10879

The WP Live Chat Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in versions up to, and including, 6.2.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04

Debido a esta vulnerabilidad, los atacantes pueden inyectar scripts o código HTML arbitrarios en la web. Actualice el complemento.

Traducción automática del texto original de la fuente. Ver original

Fuente: Patchstack

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.02

Debido a esta vulnerabilidad, los atacantes pueden inyectar scripts o código HTML arbitrarios en la web. Actualice el complemento.

Traducción automática del texto original de la fuente. Ver original

Fuente: Patchstack

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0

Because of this vulnerability, unauthenticated remote attackers can execute arbitrary SQL commands. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0

The WP Live Chat Support plugin for WordPress is vulnerable to blind SQL Injection via the 'cid' and 'status' parameter in versions up to, and including, 4.3.5 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0

The WP Live Chat Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wplc_update_admin_chat_table’ parameter in versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2014-10386

The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.2.0

There is a Stored Cross-Site Scripting (XSS) in WP-Live Chat by 3CX v. 8.1.9 By 3CX within the Quick Response function. Due to the nature of this vulnerability, a malicious attack with access to a WordPress multisite and permissions to this plugin can craft a malformed JavaScript payload.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.08

The 3CX Live Chat WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04

The 3CX Live Chat WordPress plugin was affected by a Stored Cross-Site Scripting (XSS) security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0

The 3CX Live Chat WordPress plugin was affected by an Unauthenticated Blind SQL Injection security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.