CVE · Medium

CVE-2018-11105 — 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.08

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-11105 3CX Free Live Chat, Calls & Messaging [wp-live-chat-support] < 8.0.08 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 8.0.08 8.0.08 2018-05-15

CVE-2018-11105

The wp-live-chat-support plugin before version 8.0.08 contains a stored cross-site scripting vulnerability in the name and email fields of the chat initiation endpoint. An attacker can inject malicious scripts through these fields when starting a new chat conversation, which are then stored and executed when an administrator views the chat. This issue represents an incomplete remediation of a previous vulnerability identified as CVE-2018-9864.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.