PT-2019-12827 · WordPress · Wp Live Chat Support
Published
2019-06-11
·
Updated
2021-08-12
·
CVE-2019-12498
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WP Live Chat Support plugin versions prior to 8.0.33
Description
The issue allows unauthorized remote attackers to steal chat logs and manipulate sessions due to certain REST API calls being accepted without invoking the
wplc api permission check protection mechanism. Over 50,000 businesses are potentially affected.Recommendations
For versions prior to 8.0.33, update to version 8.0.33 or later to resolve the issue. As a temporary workaround, consider restricting access to the REST API endpoints until the update is applied.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Live Chat Support