PLUGIN SECURITY

Is 3CX Live Chat safe?

Chat with your website visitors in real-time for free! Engage with your customers and increase sales.

What this plugin does

  • Slug: wp-live-chat-support
  • Author: WP-LiveChat
  • 100000+ active installs
  • 92/100 rating (821 reviews on wordpress.org)
  • 4054579 all-time downloads
  • On WordPress.org since 2013-01-06

free live chatlive chatlive helplive supportwordpress live chat

Maintenance status

  • Last updated: 2026-06-29 11:48am GMT
  • Tested up to WordPress: 7.0.0
  • Requires PHP: 5.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

12 known CVEs on file for 3CX Live Chat. Reported between 2014 and 2022.

CVE Vulnerability Type Severity Affected Fixed in Published Status
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 9.4.3 Unknown < 9.4.3 9.4.3 2022-04-28
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.2.0 Unknown < 8.2.0 8.2.0 2020-07-12
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.2.0 Unknown < 8.2.0 8.2.0 2020-07-12
CVE-2019-12498 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.33 Missing Authorization Critical 9.8 < 8.0.33 8.0.33 2019-05-31
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.27 Unknown < 8.0.27 8.0.27 2019-05-21
CVE-2019-14950 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.27 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 8.0.27 8.0.27 2019-05-15
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.18 Unknown < 8.0.18 8.0.18 2019-03-12
CVE-2019-9913, CVE-2018-18460 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.18 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 8.0.18 8.0.18 2019-02-05

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 9.4.3

The 3CX Live Chat plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 9.4.2 via the evaluate_php_template() function. This allows authenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

Source: Wordfence

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.2.0

Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by Chevon Phillip in WordPress 3CX Live Chat plugin (versions <= 8.1.9).

Source: Patchstack

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.2.0

The WP Live Chat Support for WordPress is vulnerable to Stored Cross-Site Scripting via the quick response and post functions in versions up to, and including, 8.1.9 due to insufficient input sanitization and output escaping. This makes it possible for subscriber-level attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2019-12498

The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.

Source: CVE.org

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.27

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability found by John Castro (Sucuri) in WordPress WP Live Chat Support plugin (versions <= 8.0.26).

Source: Patchstack

CVE-2019-14950

The 3CX Live Chat WordPress plugin was affected by an Unauthenticated Stored XSS security vulnerability.

Source: WPScan

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.18

Reflected Cross-Site Scripting (XSS) vulnerability found by Tim Coen in WordPress WP Live Chat Support plugin (versions <= 8.0.17).

Source: Patchstack

CVE-2019-9913, CVE-2018-18460

The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.

Source: CVE.org

+ 25 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-18460 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.18 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 8.0.18 8.0.18 2018-10-17
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.08 Unknown < 8.0.08 8.0.08 2018-05-17
CVE-2018-11105 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.08 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 8.0.08 8.0.08 2018-05-15
CVE-2018-9864 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.06 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 8.0.06 8.0.06 2018-04-09
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.06 Unknown < 8.0.06 8.0.06 2018-04-09
CVE-2017-18507 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 7.1.05 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 7.1.05 7.1.05 2017-08-02
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 7.1.05 Unknown < 7.1.05 7.1.05 2017-07-30
CVE-2017-18508 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 1.7.03 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.7.03 1.7.03 2017-07-10
CVE-2017-2187 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 7.0.07 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 7.0.07 7.0.07 2017-05-16
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04 Unknown < 6.2.04 6.2.04 2016-09-11
CVE-2016-10879 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 6.2.04 6.2.04 2016-08-01
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04 Unknown < 6.2.04 6.2.04 2016-08-01
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.02 Unknown < 6.2.02 6.2.02 2016-07-11
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0 Unknown < 4.4.0 4.4.0 2015-07-06
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0 Unknown < 4.4.0 4.4.0 2015-07-06
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0 Unknown < 4.4.0 4.4.0 2015-07-06
CVE-2014-10386 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.1.0 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Medium 6.1 < 4.1.0 4.1.0 2014-07-20
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.2.0 Unknown < 8.2.0 8.2.0
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.08 Unknown < 8.0.08 8.0.08
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04 Unknown < 6.2.04 6.2.04
3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0 Unknown < 4.4.0 4.4.0
WP Live Chat Support < 4.4.0 - Unauthenticated Blind SQL Injection Unknown < 4.4.0 4.4.0
WP Live Chat Support < 6.2.04 - Stored Cross-Site Scripting (XSS) Unknown < 6.2.04 6.2.04
CVE-2018-10234 WP Live Chat Support < 8.0.08 - Cross-Site Scripting (XSS) Unknown < 8.0.08 8.0.08
WP-Live Chat by 3CX < 8.2.0 - Authenticated Stored Cross-Site Scripting Unknown < 8.2.0 8.2.0

CVE-2018-18460

XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admin/admin.php wplivechat-menu-gdpr-page request.

Source: CVE.org

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.08

Authenticated Cross-Site Scripting (XSS) vulnerability found by Riccardo ten Cate in WordPress WP Live Chat Support plugin (versions <=8.0.07).

Source: Patchstack

CVE-2018-11105

There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplc_name) and "email" (aka wplc_email) input fields to wp-json/wp_live_chat_support/v1/start_chat whenever a malicious attacker would initiate a new chat with an administrator. NOTE: this issue exists because of an incomplete fix for CVE-2018-9864.

Source: CVE.org

CVE-2018-9864

An unauthenticated user can inject arbitrary javascript code in the admin panel by using the text field "Name" of WP Live Chat Support. The arbitrary code runs on the page wplivechat-menu-history. In the file wp-live-chat-support.php there is no sanitization of $result->id (row 4439). WP Live Chat Support 8.0.05 is vulnerable, probably earlier versions too. The vulnerability is fixed in WP Live Cjat Support 8.0.06

Source: WPScan

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.06

Unauthenticated Stored XSS vulnerability found by Luigi in WordPress WP Live Chat Support plugin (versions <=8.0.05).

Source: Patchstack

CVE-2017-18507

WP Live Chat Support is vulnerable by sending XSS payloads through chat.

Source: WPScan

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 7.1.05

Cross-Site Scripting (XSS) vulnerability discovered by Omaid Faizyar in WordPress WP Live Chat Support plugin version 7.1.0.4 and earlier versions. The vulnerability allows an attacker to send Cross-Site Scripting (XSS) payloads by chat. Update the WordPress WP Live Chat Support plugin to the latest available version (at least 7.1.05).

Source: Patchstack

CVE-2017-18508

The 3CX Live Chat WordPress plugin was affected by a XSS security vulnerability.

Source: WPScan

CVE-2017-2187

The WordPress plugin "WP Live Chat Support" provided by CODECABIN_ contains a cross-site scripting vulnerability (CWE-79). Chris Liu reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Source: jvndb.jvn.jp

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04

WP Live Chat Support Plugin 6.2.03 is prone to a Cross-site scripting (XSS) vulnerability. This vulnerability allows to perform a number of arbitrary actions via wp-live-chat-support/functions.php (line 1233). Update the plugin. This vulnerability was fixed in 6.2.04.

Source: Patchstack

CVE-2016-10879

The WP Live Chat Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in versions up to, and including, 6.2.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Source: Patchstack

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.02

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Source: Patchstack

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0

Because of this vulnerability, unauthenticated remote attackers can execute arbitrary SQL commands. Update the plugin.

Source: Patchstack

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0

The WP Live Chat Support plugin for WordPress is vulnerable to blind SQL Injection via the 'cid' and 'status' parameter in versions up to, and including, 4.3.5 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Source: Wordfence

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0

The WP Live Chat Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wplc_update_admin_chat_table’ parameter in versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2014-10386

The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.

Source: CVE.org

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.2.0

There is a Stored Cross-Site Scripting (XSS) in WP-Live Chat by 3CX v. 8.1.9 By 3CX within the Quick Response function. Due to the nature of this vulnerability, a malicious attack with access to a WordPress multisite and permissions to this plugin can craft a malformed JavaScript payload.

Source: WPScan

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.08

The 3CX Live Chat WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Source: WPScan

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 6.2.04

The 3CX Live Chat WordPress plugin was affected by a Stored Cross-Site Scripting (XSS) security vulnerability.

Source: WPScan

3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 4.4.0

The 3CX Live Chat WordPress plugin was affected by an Unauthenticated Blind SQL Injection security vulnerability.

Source: WPScan

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.