CVE-2018-9864: XSS
Published Apr 9, 2018
·Updated
The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.
Affected Software
1 affected component
3CX Live Chat Wordpress<8.0.06
Event History
Apr 9, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-9864?
CVE-2018-9864 is a vulnerability in the WP Live Chat Support plugin before version 8.0.06 for WordPress, which allows for stored XSS through the Name field.
2
How severe is CVE-2018-9864?
CVE-2018-9864 has a severity keyword of 'medium' and a severity value of 6.1 out of 10.
3
How does CVE-2018-9864 affect software?
The affected software is the WP Live Chat Support plugin before version 8.0.06 for WordPress.
4
How can I fix CVE-2018-9864?
To fix CVE-2018-9864, you should update the WP Live Chat Support plugin to version 8.0.06 or higher.
5
What is the Common Weakness Enumeration (CWE) for CVE-2018-9864?
The CWE for CVE-2018-9864 is CWE-79, which is the category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').