PT-2022-14615 · WordPress · Free Live Chat Support

Masaki Sunayama

·

Published

2022-07-18

·

Updated

2024-01-11

·

CVE-2022-2039

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Free Live Chat Support plugin for WordPress versions up to, and including 1.0.11
Description The issue is due to missing nonce protection on the livesupporti settings() function found in the ~/livesupporti.php file. This allows unauthenticated attackers to inject malicious web scripts into the page if they can trick a site's administrator into performing an action such as clicking on a link.
Recommendations For versions up to, and including 1.0.11, update to a version that includes nonce protection for the livesupporti settings() function to prevent Cross-Site Request Forgery attacks. As a temporary workaround, consider restricting access to the livesupporti settings() function until a patch is available.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-2039

Affected Products

Free Live Chat Support