CVE · Medium

CVE-2017-2187 — 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 7.0.07

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2017-2187 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 7.0.07 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 7.0.07 7.0.07 2017-05-16

CVE-2017-2187

The WordPress plugin "WP Live Chat Support" provided by CODECABIN_ contains a cross-site scripting vulnerability (CWE-79). Chris Liu reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Source: jvndb.jvn.jp

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.