CVE · Medium

CVE-2018-11105 — 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.08

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-11105 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.08 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 8.0.08 8.0.08 2018-05-15

CVE-2018-11105

There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplc_name) and "email" (aka wplc_email) input fields to wp-json/wp_live_chat_support/v1/start_chat whenever a malicious attacker would initiate a new chat with an administrator. NOTE: this issue exists because of an incomplete fix for CVE-2018-9864.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.