The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.
References
Link | Resource |
---|---|
https://www.youtube.com/watch?v=eHG1pWaez9w | Exploit Third Party Advisory |
https://www.gubello.me/blog/wp-live-chat-support-8-0-05-stored-xss/ | Exploit Third Party Advisory |
https://wordpress.org/plugins/wp-live-chat-support/#developers | Third Party Advisory |
Configurations
Information
Published : 2018-04-09 10:29
Updated : 2018-05-15 11:30
NVD link : CVE-2018-9864
Mitre link : CVE-2018-9864
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
wp-livechat
- _wp_live_chat_support