Skip to content
Noroxi

3CX Free Live Chat, Calls & Messaging

wp-live-chat-support · plugin

Known security vulnerabilities for 3CX Free Live Chat, Calls & Messaging. Find out in seconds which version runs on your site with WP Lens.

10 known vulnerabilities

2 critical · 10 exploitable without logging in · 1 with public exploit code · latest Mar 20, 2020

Listed on wordpress.org · latest 10.0.18 · last updated Jun 29, 2026 · 100K+ installs

wordpress.org status checked on Oct 2, 2026

Vulnerabilities

  • CVE-2019-12498unauthenticated

    The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check pr

    Critical 9.8
  • CVE-2019-11185unauthenticated

    The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability.

    Critical 9.8
  • CVE-2014-10386unauthenticated · needs a click

    The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.

    Medium 6.1
  • CVE-2017-18507unauthenticated · needs a click

    The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS.

    Medium 6.1
  • CVE-2019-14950unauthenticated · needs a click

    The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.

    Medium 6.1
  • CVE-2017-18508unauthenticated · needs a click

    The wp-live-chat-support plugin before 7.1.03 for WordPress has XSS.

    Medium 6.1
  • CVE-2016-10879unauthenticated · needs a click

    The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS.

    Medium 6.1
  • CVE-2018-18460unauthenticated · needs a click

    XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admin/admin.php wplivech

    Medium 6.1
  • CVE-2018-11105unauthenticated · needs a click

    There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplc_name) and "emai

    Medium 6.1
  • CVE-2018-9864unauthenticated · needs a click

    The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.

    Medium 6.1

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory