CVE-2018-11105: XSS
There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplcname) and "email" (aka wplcemail) input fields to wp-json/wplivechatsupport/v1/startchat whenever a malicious attacker would initiate a new chat with an administrator. NOTE: this issue exists because of an incomplete fix for CVE-2018-9864.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for the wp-live-chat-support plugin?
The vulnerability ID for the wp-live-chat-support plugin is CVE-2018-11105.
What is the severity of CVE-2018-11105?
The severity of CVE-2018-11105 is medium.
How does CVE-2018-11105 affect the wp-live-chat-support plugin?
CVE-2018-11105 allows for stored cross-site scripting (XSS) in the wp-live-chat-support plugin.
How can the wp-live-chat-support plugin be exploited through CVE-2018-11105?
CVE-2018-11105 can be exploited by a malicious attacker initiating a new chat with an administrator, using malicious input in the "name" and "email" fields.
Is there a fix available for CVE-2018-11105?
Yes, a fix is available for CVE-2018-11105. It is recommended to update the wp-live-chat-support plugin to version 8.0.08 or later.