PT-2025-21786 · WordPress · Wise Chat

Tim Coen

·

Published

2025-05-17

·

Updated

2025-05-22

·

CVE-2024-13613

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Wise Chat plugin for WordPress versions prior to 3.3.4
Description: The issue allows unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory, which can contain file attachments included in chat messages. This is possible due to the exposure of sensitive information in all versions up to, and including, 3.3.3 via the 'uploads' directory.
Recommendations: For Wise Chat plugin for WordPress versions prior to 3.3.4, update to version 3.3.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the /wp-content/uploads directory to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-13613

Affected Products

Wise Chat