Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat
Chat Widget adds a floating customer-support widget connecting visitors with messaging, calling, and chat channels.
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat (chat-widget-floating-customer-support-button-for-30-channels-supporting-sms-call) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 6.5.
chat-widget-floating-customer-support-button-for-30-channels-supporting-sms-callCVE-2026-16548: Chat Widget public responses permit unbounded arbitrary-file storage
Chat Widget before 1.8.2 accepts files through its public response endpoint without validating their type, extension, contents or size when response storage or mail forwarding is configured. An unauthenticated attacker can consume disk space or host arbitrary content under the uploads directory. The plugin discards the original extension and stores each file under a bare UUID, so the disclosed behavior does not provide code execution or stored XSS. The advisory does not disclose the endpoint route, upload field or storage path.
| Safe version |
|
||
|---|---|---|---|
| Aug 04, 2026 |
CVE-2026-16548
Chat Widget public responses permit unbounded arbitrary-file storage
Chat Widget before 1.8.2 accepts files through its public response endpoint without validating their type, extension, contents or size when response storage or mail forwarding is configured. An unauthenticated attacker can consume disk space or host arbitrary content under the uploads directory. The plugin discards the original extension and stores each file under a bare UUID, so the disclosed behavior does not provide code execution or stored XSS. The advisory does not disclose the endpoint route, upload field or storage path.
|
1.8.2 |
CVE6.5
NVDPending
|