← WordPress Vulnerabilities
WordPress security by component

Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat

Chat Widget adds a floating customer-support widget connecting visitors with messaging, calling, and chat channels.

Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat (chat-widget-floating-customer-support-button-for-30-channels-supporting-sms-call) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 6.5.

Plugin slug: chat-widget-floating-customer-support-button-for-30-channels-supporting-sms-call

CVE-2026-16548: Chat Widget public responses permit unbounded arbitrary-file storage

Chat Widget before 1.8.2 accepts files through its public response endpoint without validating their type, extension, contents or size when response storage or mail forwarding is configured. An unauthenticated attacker can consume disk space or host arbitrary content under the uploads directory. The plugin discards the original extension and stores each file under a bare UUID, so the disclosed behavior does not provide code execution or stored XSS. The advisory does not disclose the endpoint route, upload field or storage path.

PublishedAug 04, 2026
Known safe version1.8.2
Published vulnerabilities for chat-widget-floating-customer-support-button-for-30-channels-supporting-sms-call
Safe version
Aug 04, 2026 CVE-2026-16548
Chat Widget public responses permit unbounded arbitrary-file storage
Chat Widget before 1.8.2 accepts files through its public response endpoint without validating their type, extension, contents or size when response storage or mail forwarding is configured. An unauthenticated attacker can consume disk space or host arbitrary content under the uploads directory. The plugin discards the original extension and stores each file under a bare UUID, so the disclosed behavior does not provide code execution or stored XSS. The advisory does not disclose the endpoint route, upload field or storage path.
1.8.2
CVE6.5
NVDPending