CVE-2019-12498: Critical severity 3cx live chat vulnerability
Published Mar 20, 2020
·Updated
The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplcapipermissioncheck protection mechanism.
Affected Software
1 affected component
3CX Live Chat Wordpress<8.0.33
Remediation
Event History
Mar 20, 2020
CVE Published
via MITRE·06:37 PM
Data Sourced
via MITRE·06:37 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2019-12498.
2
What is the severity of CVE-2019-12498?
CVE-2019-12498 has a severity rating of 9.8 (Critical).
3
Which software is affected by CVE-2019-12498?
The WP Live Chat Support plugin version up to 8.0.32 for WordPress is affected by CVE-2019-12498.
4
What is the protection mechanism missing in WP Live Chat Support plugin?
The WP Live Chat Support plugin before 8.0.33 does not invoke the wplc_api_permission_check protection mechanism.
5
How can I fix the vulnerability in WP Live Chat Support plugin?
To fix the vulnerability, update the WP Live Chat Support plugin to version 8.0.33 or higher.