First published: Mon Apr 09 2018(Updated: )
The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
3cx Live Chat | <8.0.06 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9864 is a vulnerability in the WP Live Chat Support plugin before version 8.0.06 for WordPress, which allows for stored XSS through the Name field.
CVE-2018-9864 has a severity keyword of 'medium' and a severity value of 6.1 out of 10.
The affected software is the WP Live Chat Support plugin before version 8.0.06 for WordPress.
To fix CVE-2018-9864, you should update the WP Live Chat Support plugin to version 8.0.06 or higher.
The CWE for CVE-2018-9864 is CWE-79, which is the category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').