← WordPress Vulnerabilities
WordPress security by component

Live Chat

Live Chat is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Mar 22, 2019; the highest CVE/CNA score is 9.8.

Plugin slug: live-chat

CVE-2019-9913: Live Chat: Cross-site scripting

Live Chat is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedMar 22, 2019
Safe version guidanceSee mitigation notes
Safe version
Mar 22, 2019 CVE-2019-9913
Live Chat: Cross-site scripting
Live Chat is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jul 02, 2018 CVE-2018-12426
Live Chat: Code execution
Live Chat is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVD9.8
Jun 09, 2017 CVE-2017-2187
Live Chat: Cross-site scripting
Live Chat is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1