CVE · Medium

CVE-2018-9864 — 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.06

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-9864 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.06 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 8.0.06 8.0.06 2018-04-09

CVE-2018-9864

An unauthenticated user can inject arbitrary javascript code in the admin panel by using the text field "Name" of WP Live Chat Support. The arbitrary code runs on the page wplivechat-menu-history. In the file wp-live-chat-support.php there is no sanitization of $result->id (row 4439). WP Live Chat Support 8.0.05 is vulnerable, probably earlier versions too. The vulnerability is fixed in WP Live Cjat Support 8.0.06

Source: WPScan

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.