12 CVEs conocidos registrados para 3CX Live Chat.
Reportadas entre 2014 y 2022.
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 9.4.3
The 3CX Live Chat plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 9.4.2 via the evaluate_php_template() function. This allows authenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
+ 25 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2018-18460
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.18 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 8.0.18
|
8.0.18 |
2018-10-17 |
—
|
|
—
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.08 |
— |
Desconocido
|
< 8.0.08
|
8.0.08 |
2018-05-17 |
—
|
|
CVE-2018-11105
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.08 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 8.0.08
|
8.0.08 |
2018-05-15 |
—
|
|
CVE-2018-9864
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.06 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 8.0.06
|
8.0.06 |
2018-04-09 |
—
|
|
—
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.06 |
— |
Desconocido
|
< 8.0.06
|
8.0.06 |
2018-04-09 |
—
|
|
CVE-2017-18507
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 7.1.05 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 7.1.05
|
7.1.05 |
2017-08-02 |
—
|
|
—
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 7.1.05 |
— |
Desconocido
|
< 7.1.05
|
7.1.05 |
2017-07-30 |
—
|
|
CVE-2017-18508
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 1.7.03 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 1.7.03
|
1.7.03 |
2017-07-10 |
—
|
|
CVE-2017-2187
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 7.0.07 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 7.0.07
|
7.0.07 |
2017-05-16 |
—
|
|
—
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04 |
— |
Desconocido
|
< 6.2.04
|
6.2.04 |
2016-09-11 |
—
|
|
CVE-2016-10879
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 6.2.04
|
6.2.04 |
2016-08-01 |
—
|
|
—
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04 |
— |
Desconocido
|
< 6.2.04
|
6.2.04 |
2016-08-01 |
—
|
|
—
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.02 |
— |
Desconocido
|
< 6.2.02
|
6.2.02 |
2016-07-11 |
—
|
|
—
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0 |
— |
Desconocido
|
< 4.4.0
|
4.4.0 |
2015-07-06 |
—
|
|
—
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0 |
— |
Desconocido
|
< 4.4.0
|
4.4.0 |
2015-07-06 |
—
|
|
—
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0 |
— |
Desconocido
|
< 4.4.0
|
4.4.0 |
2015-07-06 |
—
|
|
CVE-2014-10386
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.1.0 |
Neutralización incorrecta de elementos especiales en la salida usada por un componente posterior (inyección) |
Media
6,1
|
< 4.1.0
|
4.1.0 |
2014-07-20 |
—
|
|
—
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.2.0 |
— |
Desconocido
|
< 8.2.0
|
8.2.0 |
— |
—
|
|
—
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.08 |
— |
Desconocido
|
< 8.0.08
|
8.0.08 |
— |
—
|
|
—
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04 |
— |
Desconocido
|
< 6.2.04
|
6.2.04 |
— |
—
|
|
—
|
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0 |
— |
Desconocido
|
< 4.4.0
|
4.4.0 |
— |
—
|
|
—
|
WP Live Chat Support < 4.4.0 - Unauthenticated Blind SQL Injection |
— |
Desconocido
|
< 4.4.0
|
4.4.0 |
— |
—
|
|
—
|
WP Live Chat Support < 6.2.04 - Stored Cross-Site Scripting (XSS) |
— |
Desconocido
|
< 6.2.04
|
6.2.04 |
— |
—
|
|
CVE-2018-10234
|
WP Live Chat Support < 8.0.08 - Cross-Site Scripting (XSS) |
— |
Desconocido
|
< 8.0.08
|
8.0.08 |
— |
—
|
|
—
|
WP-Live Chat by 3CX < 8.2.0 - Authenticated Stored Cross-Site Scripting |
— |
Desconocido
|
< 8.2.0
|
8.2.0 |
— |
—
|
CVE-2018-18460
XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admin/admin.php wplivechat-menu-gdpr-page request.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.08
Authenticated Cross-Site Scripting (XSS) vulnerability found by Riccardo ten Cate in WordPress WP Live Chat Support plugin (versions <=8.0.07).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2018-11105
There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplc_name) and "email" (aka wplc_email) input fields to wp-json/wp_live_chat_support/v1/start_chat whenever a malicious attacker would initiate a new chat with an administrator. NOTE: this issue exists because of an incomplete fix for CVE-2018-9864.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2018-9864
An unauthenticated user can inject arbitrary javascript code in the admin panel by using the text field "Name" of WP Live Chat Support. The arbitrary code runs on the page wplivechat-menu-history.
In the file wp-live-chat-support.php there is no sanitization of $result->id (row 4439).
WP Live Chat Support 8.0.05 is vulnerable, probably earlier versions too.
The vulnerability is fixed in WP Live Cjat Support 8.0.06
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.06
Unauthenticated Stored XSS vulnerability found by Luigi in WordPress WP Live Chat Support plugin (versions <=8.0.05).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2017-18507
WP Live Chat Support is vulnerable by sending XSS payloads through chat.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 7.1.05
Cross-Site Scripting (XSS) vulnerability discovered by Omaid Faizyar in WordPress WP Live Chat Support plugin version 7.1.0.4 and earlier versions. The vulnerability allows an attacker to send Cross-Site Scripting (XSS) payloads by chat.
Update the WordPress WP Live Chat Support plugin to the latest available version (at least 7.1.05).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2017-18508
The 3CX Live Chat WordPress plugin was affected by a XSS security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
CVE-2017-2187
The WordPress plugin "WP Live Chat Support" provided by CODECABIN_ contains a cross-site scripting vulnerability (CWE-79). Chris Liu reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
jvndb.jvn.jp
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04
WP Live Chat Support Plugin 6.2.03 is prone to a Cross-site scripting (XSS) vulnerability. This vulnerability allows to perform a number of arbitrary actions via wp-live-chat-support/functions.php (line 1233).
Update the plugin. This vulnerability was fixed in 6.2.04.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2016-10879
The WP Live Chat Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in versions up to, and including, 6.2.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04
Debido a esta vulnerabilidad, los atacantes pueden inyectar scripts o código HTML arbitrarios en la web.
Actualice el complemento.
Traducción automática del texto original de la fuente.
Ver original
Fuente:
Patchstack
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.02
Debido a esta vulnerabilidad, los atacantes pueden inyectar scripts o código HTML arbitrarios en la web.
Actualice el complemento.
Traducción automática del texto original de la fuente.
Ver original
Fuente:
Patchstack
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0
Because of this vulnerability, unauthenticated remote attackers can execute arbitrary SQL commands.
Update the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0
The WP Live Chat Support plugin for WordPress is vulnerable to blind SQL Injection via the 'cid' and 'status' parameter in versions up to, and including, 4.3.5 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0
The WP Live Chat Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wplc_update_admin_chat_table’ parameter in versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2014-10386
The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.2.0
There is a Stored Cross-Site Scripting (XSS) in WP-Live Chat by 3CX v. 8.1.9 By 3CX within the Quick Response function. Due to the nature of this vulnerability, a malicious attack with access to a WordPress multisite and permissions to this plugin can craft a malformed JavaScript payload.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.08
The 3CX Live Chat WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04
The 3CX Live Chat WordPress plugin was affected by a Stored Cross-Site Scripting (XSS) security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0
The 3CX Live Chat WordPress plugin was affected by an Unauthenticated Blind SQL Injection security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.